CVE-2009-3699

N/A Unknown
Published: October 15, 2009 Modified: April 23, 2026
View on NVD

Description

Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/36978
Source: cve@mitre.org
Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ62572
Source: cve@mitre.org
Vendor Advisory
http://www.osvdb.org/58726
Source: cve@mitre.org
http://www.securityfocus.com/bid/36615
Source: cve@mitre.org
Exploit Patch
http://www.vupen.com/english/advisories/2009/2846
Source: cve@mitre.org
Patch Vendor Advisory
http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=825
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://secunia.com/advisories/36978
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securitytracker.com/id?1022996
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ61628
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ61717
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ62123
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ62237
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ62569
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ62570
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ62571
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ibm.com/support/docview.wss?uid=isg1IZ62572
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ62672
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/58726
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/36615
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Patch
http://www.vupen.com/english/advisories/2009/2846
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53681
Source: af854a3a-2127-422b-91ae-364da2661108

36 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
78.9%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

ibm