IBM Informix 'librpc.dll' Spoofing Vulnerability
BID:47875
Info
IBM Informix 'librpc.dll' Spoofing Vulnerability
| Bugtraq ID: | 47875 |
| Class: | Design Error |
| CVE: |
CVE-2011-1210 |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2011 12:00AM |
| Updated: | May 16 2011 12:00AM |
| Credit: | Anonymous researcher working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
IBM Informix IDS 11.70 IBM Informix IDS 11.50.xC8 IBM Informix IDS 11.50.xC5 IBM Informix IDS 11.50.xC3 IBM Informix IDS 11.50.xC1 IBM Informix IDS 11.50 IBM Informix IDS 11.10.xC4 IBM Informix IDS 11.10.xC3 IBM Informix IDS 11.10.xC2W2 IBM Informix IDS 11.10.xC2 IBM Informix IDS 11.10.TC3 IBM Informix IDS 11.10 |
| Not Vulnerable: |
IBM Informix IDS 11.70.xC2X1 IBM Informix IDS 11.50.xC8W4 IBM Informix IDS 11.10.TC3W2X1 IBM Informix IDS 11.10.FC3W1X1 |
Discussion
IBM Informix 'librpc.dll' Spoofing Vulnerability
IBM Informix is prone to a vulnerability that allows attackers to spoof source addresses.
An attacker can exploit this issue to spoof a source address, allowing the attacker to perform denial-of-service attacks or eavesdrop on process communications.
IBM Informix is prone to a vulnerability that allows attackers to spoof source addresses.
An attacker can exploit this issue to spoof a source address, allowing the attacker to perform denial-of-service attacks or eavesdrop on process communications.
Exploit / POC
IBM Informix 'librpc.dll' Spoofing Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
IBM Informix 'librpc.dll' Spoofing Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
IBM Informix 'librpc.dll' Spoofing Vulnerability
References:
References:
- Informix Homepage (IBM)
- ZDI-11-168: Multiple Vendor librpc.dll Remote Information Disclosure Vulnerabil (ZDI Disclosures
) - IC76177: SECURITY: CVE-2011-1210: IBM INFORMIX SERVERS ON WINDOWS SUBJECT TO REM (IBM)
- IC76178: SECURITY: CVE-2011-1210: IBM INFORMIX SERVERS ON WINDOWS SUBJECT TO REM (IBM)
- IC76179: SECURITY: CVE-2011-1210: IBM INFORMIX SERVERS ON WINDOWS SUBJECT TO REM (IBM)
- ZDI-11-168 Multiple Vendor librpc.dll Remote Information Disclosure Vulnerabilit (Zero Day Initiative)