CVE-2010-2090

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/05/2010
Last modified:
11/04/2025

Description

The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:communications_server:6.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:communications_server:6.3.1.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:communications_server:6.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:communications_server:6.3.1.0:*:*:*:*:*:*:*