PT-2012-1207 · Unixodbc+1 · Unixodbc+1

Felipe Pena

·

Publicado

2012-05-14

·

Atualizado

2024-08-06

·

CVE-2012-2658

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions unixODBC version 2.3.1
Description The issue is related to a buffer overflow in the SQLDriverConnect function, which can be triggered by a long string in the DRIVER option. This can cause a denial of service (crash). The ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue might not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker.
Recommendations For unixODBC version 2.3.1, consider restricting access to the SQLDriverConnect function to minimize the risk of exploitation. As a temporary workaround, avoid using long strings in the DRIVER option until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1267
BDU:2021-01400
CVE-2012-2658

Produtos afetados

Alt Linux
Unixodbc