aix.software.ibm.com
http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc CVE-2010-4435
Multiple Vendor Calendar Manager - Remote Code Execution
Record summary
CVE-2010-4435 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMultiple Vendor Calendar Manager - Remote Code ExecutionExploitDB exploitby Rodrigo Rubira BrancoNot analyzed1 file
References
Showing 12 of 19HPSBUX02628Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02702395 70569vdb entry
http://osvdb.org/70569 42984Third-party advisory
http://secunia.com/advisories/42984 43258Third-party advisory
http://secunia.com/advisories/43258 8069Third-party advisory
http://securityreason.com/securityalert/8069 16137exploit
http://www.exploit-db.com/exploits/16137 oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html 20110208 ZDI-11-062: Multiple Vendor Calendar Manager RPC Service Remote Code Execution Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/516284/100/0/threaded 20110208 CVE-2010-4435 - Multiple Vendor Calendar Manager Remote Code Executionmailing list
http://www.securityfocus.com/archive/1/516304/100/0/threaded 45853vdb entry
http://www.securityfocus.com/bid/45853 46261vdb entry
http://www.securityfocus.com/bid/46261