PT-2008-2526 · Sybase · Sybase Mobilink+1

Luigi Auriemma

·

Publicado

2008-02-22

·

Atualizado

2018-10-15

·

CVE-2008-0912

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sybase MobiLink versions 10.0.1.3629 and earlier SQL Anywhere Developer Edition versions 10.0.1.3415 and earlier
Description The issue is related to multiple heap-based buffer overflows in the mlsrv10.exe component. This can be exploited by remote attackers via a long username, version, or remote ID. Successful exploitation can lead to the execution of arbitrary code or cause a denial of service, resulting in a daemon crash.
Recommendations For Sybase MobiLink versions 10.0.1.3629 and earlier, consider updating to a version later than 10.0.1.3629 to resolve the issue. For SQL Anywhere Developer Edition versions 10.0.1.3415 and earlier, consider updating to a version later than 10.0.1.3415 to resolve the issue. As a temporary workaround, consider restricting the length of the username, version, and remote ID to prevent exploitation until a patch is available.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0912

Produtos afetados

Sql Anywhere Developer Edition
Sybase Mobilink