Multiple Vendor 'rpc.pcnfsd' Integer Overflow Vulnerability
BID:40248
Info
Multiple Vendor 'rpc.pcnfsd' Integer Overflow Vulnerability
| Bugtraq ID: | 40248 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1039 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2010 12:00AM |
| Updated: | Jul 19 2010 06:36AM |
| Credit: | Rodrigo Rubira Branco from the Check Point Vulnerability Discovery Team (VDT) |
| Vulnerable: |
SGI IRIX 6.5 20 SGI IRIX 6.5 .19m SGI IRIX 6.5 .19f SGI IRIX 6.5 IBM Virtual I/O Server (VIOS) 2.1 IBM Virtual I/O Server (VIOS) 1.5.2 IBM Virtual I/O Server (VIOS) 2.1 IBM Virtual I/O Server (VIOS) 1.5 IBM AIX 6.1.3 IBM AIX 6.1.2 IBM AIX 6.1.1 IBM AIX 5.3.10 IBM AIX 5.3.9 IBM AIX 5.3.8 IBM AIX 5.3.7 IBM AIX 5.3 L IBM AIX 6.1 IBM AIX 5.3 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: | |
Exploit / POC
Multiple Vendor 'rpc.pcnfsd' Integer Overflow Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
References
Multiple Vendor 'rpc.pcnfsd' Integer Overflow Vulnerability
References:
References:
- HP Homepage (HP)
- ONCplus Homepage (HP)
- Update Protection against Multiple Vendors rpc.pcnfsd Syslog Format String Vulne (Check Point)
- [security bulletin] HPSBUX02523 SSRT100036 rev.1 - HP-UX Running ONCPlus, Remote ([email protected])
- [security bulletin] HPSBUX02523 SSRT100036 rev.2 - HP-UX Running ONCplus rpc.pcn ([email protected])