Vulnerability Description
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Informix Dynamic Server | >= 10.0, <= 10.00.xc8 |
| Ibm | Informix Storage Manager | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/28689Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21294211Vendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=onlyVendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=onlyVendor Advisory
- http://www.securityfocus.com/bid/27485Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1019281Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/0317Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40018Third Party AdvisoryVDB Entry
- http://secunia.com/advisories/28689Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21294211Vendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=onlyVendor Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=onlyVendor Advisory
- http://www.securityfocus.com/bid/27485Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1019281Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/0317Permissions Required
FAQ
What is CVE-2008-0768?
CVE-2008-0768 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 ...
How severe is CVE-2008-0768?
CVE-2008-0768 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0768?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Informix Dynamic Server, Ibm Informix Storage Manager, Microsoft Windows.