CVE-2009-3691 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.04% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-10-13 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| ibm | informix client sdk |
| ibm | informix connect runtime |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Informix Client SDK 3.0 - '.nfx' File Integer Overflow | 2009-10-05 |
References
- http://retrogod.altervista.org/9sg_ibm_setnet32.html
- http://secunia.com/advisories/36949
- http://securitytracker.com/id?1022985
- http://www.osvdb.org/58530
- http://www.securityfocus.com/bid/36588
- http://www.vupen.com/english/advisories/2009/2834
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53644
- http://retrogod.altervista.org/9sg_ibm_setnet32.html
- http://secunia.com/advisories/36949
- http://securitytracker.com/id?1022985
- http://www.osvdb.org/58530
- http://www.securityfocus.com/bid/36588
- http://www.vupen.com/english/advisories/2009/2834
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53644
→ the Explorer · watch your stack · NVD