← All CVEs

CVE-2009-2727

high · 9.3

Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.

9.3
CVSS
26.7%
EPSS (exploit prob.)
98th
EPSS percentile
2009-08-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
ibmaix5.2
ibmaix5.2.0
ibmaix5.2.0.50
ibmaix5.2.0.54
ibmaix5.2.2
ibmaix5.2_l
ibmaix5.3
ibmaix5.3.0
ibmaix5.3.7
ibmaix5.3.8
ibmaix5.3.9
ibmaix5.3.10
ibmaix6.1
ibmaix6.1.0
ibmaix6.1.1
ibmaix6.1.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-2727