{ "schema_version": "1.4.0", "id": "GHSA-jc9g-5ggm-9q3r", "modified": "2022-05-02T03:47:45Z", "published": "2022-05-02T03:47:45Z", "aliases": [ "CVE-2009-3699" ], "details": "Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3699" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53681" }, { "type": "WEB", "url": "https://www.immunityinc.com/downloads/immpartners/aixcmsd10092009.tar.gz" }, { "type": "WEB", "url": "http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc" }, { "type": "WEB", "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=825" }, { "type": "WEB", "url": "http://secunia.com/advisories/36978" }, { "type": "WEB", "url": "http://securitytracker.com/id?1022996" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ61628" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ61717" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62123" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62237" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62569" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62570" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62571" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62572" }, { "type": "WEB", "url": "http://www.ibm.com/support/docview.wss?uid=isg1IZ62672" }, { "type": "WEB", "url": "http://www.osvdb.org/58726" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/36615" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2009/2846" } ], "database_specific": { "cwe_ids": [ "CWE-119" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2009-10-15T10:30:00Z" } }