PT-1999-1651 · Oracle · Db

Publicado

1999-12-31

·

Atualizado

2016-10-18

·

CVE-1999-1330

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: db library version 1.85.4
Description: The issue concerns the snprintf function in the db library, which fails to properly implement the size parameter. This oversight could enable attackers to exploit buffer overflows that would otherwise be prevented by a correctly implemented snprintf function.
Recommendations: For db library version 1.85.4, consider disabling the use of the snprintf function until a patch is available that properly implements the size parameter to prevent buffer overflows.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1330

Produtos afetados

Db