PoC Index

CVE-2009-3691

HIGH 9.3EPSS 7.0%

Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
7.04% chance of exploitation in the next 30 days, 94th percentile
Published
2009-10-13
Updated
2024-08-07

ExploitDB entries (1)

References

Related