漏洞关键信息 漏洞ID: - CVE-2009-2754 CVSS评分: - CVSS 2.0 Base Score: 10 - Access Vector: Network - Access Complexity: Low - Authentication: None - Confidentiality Impact: Complete - Integrity Impact: Complete - Availability Impact: Complete - CVSS 2.0 Temporal Score: 7.8 - Exploitability: Proof-of-Concept - Remediation Level: Official Fix - Report Confidence: Confirmed 影响的产品: - EMC Legato NetWorker - IBM Informix Dynamic Server 10.0 - IBM Informix Dynamic Server 11.1 修复建议: - 对于IBM Informix Dynamic Server 10: - 应用最新的Fix Pack (10.00.TC10或更高) 或 APAR IC55329。 - 对于IBM Informix Dynamic Server 11: - 应用最新的Fix Pack (11.10.TC3或更高) 或 APAR IC55330。 - 对于EMC Legato NetWorker: - 应用针对你的系统的适当补丁(ESA-08-007),该补丁可从EMC网站获取。 后果: - Gain Access 相关链接: - ZDI-10-023 - IBM Web site - EMC Web site - Offensive Security Exploit Database [04-08-2010]