CVE-2009-2727
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 27%
from disclosure to weapon458 days
Published on NVDAug 10
1st PoC+458d
metasploitJun 17
exploitation probability
27%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16930unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aix.software.ibm.com/aix/efixes/security/libtt_advisory.aschttp://risesecurity.org/advisories/RISE-2009001.txthttp://secunia.com/advisories/35505http://www.ibm.com/support/docview.wss?uid=isg1IZ52842http://www.ibm.com/support/docview.wss?uid=isg1IZ52843http://www.ibm.com/support/docview.wss?uid=isg1IZ52844http://www.ibm.com/support/docview.wss?uid=isg1IZ52845http://www.ibm.com/support/docview.wss?uid=isg1IZ52846http://www.ibm.com/support/docview.wss?uid=isg1IZ52847http://www.ibm.com/support/docview.wss?uid=isg1IZ52848http://www.ibm.com/support/docview.wss?uid=isg1IZ52849http://www.ibm.com/support/docview.wss?uid=isg1IZ52850