PT-2019-6619 · Unixodbc · Unixodbc
Felipe Pena
·
Publicado
2017-10-16
·
Atualizado
2024-06-15
·
CVE-2011-1145
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
unixODBC versions prior to 2.2.14p2
Description
The issue is related to a possible buffer overflow condition in the SQLDriverConnect() function when a large value is specified for the
SAVEFILE parameter in the connection string. This condition can occur when using the SQLDriverConnect() function with a large SAVEFILE value.Recommendations
For versions prior to 2.2.14p2, update to version 2.2.14p2 or later to resolve the issue. As a temporary workaround, consider restricting the use of large values for the
SAVEFILE parameter in the connection string to minimize the risk of exploitation.Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Unixodbc