Vulnerability Description
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Nfs\/Oncplus | <= b.11.31_09 |
| Hp | Hp-Ux | b.11.11 |
| Ibm | Aix | <= 5.3 |
| Ibm | Vios | <= 1.5 |
| Sgi | Irix | 6.5 |
Related Weaknesses (CWE)
References
- http://aix.software.ibm.com/aix/efixes/security/pcnfsd_advisory.asc
- http://marc.info/?l=bugtraq&m=127428077629933&w=2Vendor Advisory
- http://osvdb.org/64729
- http://secunia.com/advisories/39835Vendor Advisory
- http://secunia.com/advisories/39911
- http://securitytracker.com/id?1024016
- http://www.checkpoint.com/defense/advisories/public/2010/cpai-13-May.html
- http://www.ibm.com/support/docview.wss?uid=isg1IZ73590
- http://www.ibm.com/support/docview.wss?uid=isg1IZ73599
- http://www.ibm.com/support/docview.wss?uid=isg1IZ73681
- http://www.ibm.com/support/docview.wss?uid=isg1IZ73757
- http://www.ibm.com/support/docview.wss?uid=isg1IZ73874
- http://www.ibm.com/support/docview.wss?uid=isg1IZ75369
- http://www.ibm.com/support/docview.wss?uid=isg1IZ75440
- http://www.ibm.com/support/docview.wss?uid=isg1IZ75465
FAQ
What is CVE-2010-1039?
CVE-2010-1039 is a vulnerability with a CVSS score of 10.0 (HIGH). Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and...
How severe is CVE-2010-1039?
CVE-2010-1039 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1039?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Nfs\/Oncplus, Hp Hp-Ux, Ibm Aix, Ibm Vios, Sgi Irix.