PT-2006-4720 · Ibm · Ibm Informix Dynamic Server

Published

2006-08-08

·

Updated

2018-10-17

·

CVE-2006-3862

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Informix Dynamic Server (IDS) versions 9.40.TC5 through 9.40.xC7 IBM Informix Dynamic Server (IDS) versions 10.00.TC1 through 10.00.xC3
Description A buffer overflow issue allows attackers to execute arbitrary code via the SQLIDEBUG environment variable.
Recommendations For versions 9.40.TC5 through 9.40.xC7, update to a version outside of this range to resolve the issue. For versions 10.00.TC1 through 10.00.xC3, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of the SQLIDEBUG environment variable to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3862

Affected Products

Ibm Informix Dynamic Server