// For flags

CVE-2009-3691

IBM Informix Client SDK 3.0 - '.nfx' File Integer Overflow

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.

Múltiples desbordamientos de entero en setnet32.exe v3.50.0.13752 en IBM Informix Client SDK v3.0 y v3.50 y Informix Connect Runtime v3.x permite a atacantes remotos ejecutar código a su elección a través de un archivo .nfx con un (1) HostSize manipulado, y probablemente (2) ProtoSize y (3) ServerSize, campo que lanza un desbordamiento de búfer basado en pila incluyendo un campos HostList manipulado. NOTA: algunos de estos detalles fueron obtenidos a partir de información de terceros.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-10-05 First Exploit
  • 2009-10-13 CVE Reserved
  • 2009-10-13 CVE Published
  • 2024-07-03 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Informix Client Sdk
Search vendor "Ibm" for product "Informix Client Sdk"
3.0
Search vendor "Ibm" for product "Informix Client Sdk" and version "3.0"
-
Affected
Ibm
Search vendor "Ibm"
Informix Client Sdk
Search vendor "Ibm" for product "Informix Client Sdk"
3.50
Search vendor "Ibm" for product "Informix Client Sdk" and version "3.50"
-
Affected
Ibm
Search vendor "Ibm"
Informix Connect Runtime
Search vendor "Ibm" for product "Informix Connect Runtime"
3.0
Search vendor "Ibm" for product "Informix Connect Runtime" and version "3.0"
-
Affected