PT-2006-6831 · Borland · Idsql32.Dll+1
Publicado
2006-12-01
·
Atualizado
2018-10-17
·
CVE-2006-6201
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Borland idsql32.dll version 5.1.0.4
Borland idsql32.dll version 5.2.0.2
Description
The issue is related to a heap-based buffer overflow that allows remote attackers to execute arbitrary code via a long SQL statement. This is connected to the use of the
DbiQExec function.Recommendations
For version 5.1.0.4, consider restricting the length of SQL statements to prevent exploitation until a fix is available.
For version 5.2.0.2, as a temporary workaround, consider disabling the use of the
DbiQExec function in Borland Developer Studio 2006 to minimize the risk of arbitrary code execution.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Borland Developer Studio 2006
Idsql32.Dll