PT-2006-4720 · Ibm · Ibm Informix Dynamic Server
Published
2006-08-08
·
Updated
2018-10-17
·
CVE-2006-3862
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Informix Dynamic Server (IDS) versions 9.40.TC5 through 9.40.xC7
IBM Informix Dynamic Server (IDS) versions 10.00.TC1 through 10.00.xC3
Description
A buffer overflow issue allows attackers to execute arbitrary code via the
SQLIDEBUG environment variable.Recommendations
For versions 9.40.TC5 through 9.40.xC7, update to a version outside of this range to resolve the issue.
For versions 10.00.TC1 through 10.00.xC3, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting the use of the
SQLIDEBUG environment variable to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Informix Dynamic Server