PT-2004-3381 · Ibm · Ibm Informix Dynamic Server
Kf
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2489
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
IBM Informix Dynamic Server (IDS) versions prior to 9.40.xC3
Description:
The issue allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.
Recommendations:
For versions prior to 9.40.xC3, update to version 9.40.xC3 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Informix Dynamic Server