IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
BID:36615
Info
IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 36615 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-4435 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2009 12:00AM |
| Updated: | Feb 08 2011 07:50PM |
| Credit: | Rodrigo Rubira Branco and iDefense Labs |
| Vulnerable: |
IBM Virtual I/O Server (VIOS) 2.1 IBM Virtual I/O Server (VIOS) 1.5.2 IBM Virtual I/O Server (VIOS) 2.1 IBM Virtual I/O Server (VIOS) 2.0 IBM Virtual I/O Server (VIOS) 1.5 IBM Virtual I/O Server (VIOS) 1.4 IBM AIX 6.1 IBM AIX 5.3 IBM AIX 5.2 |
| Not Vulnerable: | |
Discussion
IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
IBM AIX is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data.
Remote attackers can exploit this issue to execute arbitrary code with superuser privileges, which can result in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
IBM AIX is prone to a remote stack-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data.
Remote attackers can exploit this issue to execute arbitrary code with superuser privileges, which can result in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
Exploit / POC
IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
A commercial exploit is available through the Immunity Partners program:
https://www.immunityinc.com/downloads/immpartners/aixcmsd10092009.tar.gz
The following proofs of concept and exploit are also available:
A commercial exploit is available through the Immunity Partners program:
https://www.immunityinc.com/downloads/immpartners/aixcmsd10092009.tar.gz
The following proofs of concept and exploit are also available:
Solution / Fix
IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
IBM AIX 6.1
IBM AIX 5.3
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
IBM AIX 6.1
-
IBM cmsd_fix.tar
ftp://aix.software.ibm.com/aix/efixes/security/cmsd_fix.tar
IBM AIX 5.3
-
IBM cmsd_fix.tar
ftp://aix.software.ibm.com/aix/efixes/security/cmsd_fix.tar
References
IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability
References:
References:
- AIX Homepage (IBM)
- iDefense Security Advisory 10.07.09: IBM AIX rpc.cmsd Stack Buffer Overflow Vuln (iDefense Labs
) - ZDI-11-062: Multiple Vendor Calendar Manager RPC Service Remote Code Execution (ZDI Disclosures
) - IBM AIX rpc.cmsd Stack Buffer Overflow Vulnerability (iDefense Labs)
- IBM SECURITY ADVISORY (IBM)
- ZDI-11-062 Multiple Vendor Calendar Manager RPC Service Remote Code Execution Vu (Zero Day Initiative)