10
CVSSv2

CVE-2010-1039

Published: 20/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and previous versions; IBM VIOS 2.1, 1.5, and previous versions; NFS/ONCplus B.11.31_09 and previous versions on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote malicious users to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

Vulnerable Product Search on Vulmon Subscribe to Product

hp nfs\\/oncplus

ibm aix 5.2.0

ibm aix 5.2.0.50

ibm aix 5.2.0.54

ibm aix 4.3

ibm aix 4.3.0

ibm aix 4.1.2

ibm aix 4.1.5

ibm aix 3.2.0

ibm aix 3.2.5

ibm aix 5.1l

ibm aix 5.2

ibm aix 4.3.1

ibm aix 4.3.2

ibm aix 4.1

ibm aix 4.1.3

ibm aix 4.2.1.12

ibm aix 3.1

ibm aix 3.2

ibm aix 5.1

ibm aix 5.1.0.10

ibm aix 430

ibm aix 4.3.3

ibm aix 4

ibm aix 4.1.1

ibm aix 4.2.1

ibm aix 4.2.0

ibm aix 1.3

ibm aix 6.1

ibm aix

ibm aix 5.2.2

ibm aix 5.2_l

ibm aix 3.2.4

ibm aix 4.0

ibm aix 4.1.4

ibm aix 4.2

ibm aix 2.2.1

ibm aix 1.2.1

ibm vios 1.4

ibm vios

ibm vios 2.1

sgi irix 6.5

Exploits

/************************************************************************* * Check Point Software Technologies - Vulnerability Discovery Team (VDT) * * Rodrigo Rubira Branco - <rbranco *noSPAM* checkpointcom> * * * * rpcpcnfsd syslog format string vulnerability * *************************************************************** ...