10

CVE-2010-1039

Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmAix Version <= 5.3
IbmAix Version1.2.1
IbmAix Version1.3
IbmAix Version2.2.1
IbmAix Version3.1
IbmAix Version3.2
IbmAix Version3.2.0
IbmAix Version3.2.4
IbmAix Version3.2.5
IbmAix Version4
IbmAix Version4.0
IbmAix Version4.1
IbmAix Version4.1.1
IbmAix Version4.1.2
IbmAix Version4.1.3
IbmAix Version4.1.4
IbmAix Version4.1.5
IbmAix Version4.2
IbmAix Version4.2.0
IbmAix Version4.2.1
IbmAix Version4.2.1.12
IbmAix Version4.3
IbmAix Version4.3.0
IbmAix Version4.3.1
IbmAix Version4.3.2
IbmAix Version4.3.3
IbmAix Version5.1
IbmAix Version5.1.0.10
IbmAix Version5.1l
IbmAix Version5.2
IbmAix Version5.2.0
IbmAix Version5.2.0.50
IbmAix Version5.2.0.54
IbmAix Version5.2.2
IbmAix Version5.2_l
IbmAix Version6.1
IbmAix Version430
IbmVios Version <= 1.5
IbmVios Version1.4
IbmVios Version2.1
SgiIrix Version6.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 24.36% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.