CVE-2008-0768
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.46% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ibm/informix dynamic server · ibm/informix storage manager
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28689Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21294211Vendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=onlyVendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=onlyVendor Advisory
- http://www.securityfocus.com/bid/27485Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019281Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0317Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40018Third Party Advisory, VDB Entry
- http://secunia.com/advisories/28689Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21294211Vendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=onlyVendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=onlyVendor Advisory
- http://www.securityfocus.com/bid/27485Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019281Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/0317Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40018Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.