PT-2006-6831 · Borland · Idsql32.Dll+1
Published
2006-12-01
·
Updated
2018-10-17
·
CVE-2006-6201
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Borland idsql32.dll version 5.1.0.4
Borland idsql32.dll version 5.2.0.2
Description
The issue is related to a heap-based buffer overflow that allows remote attackers to execute arbitrary code via a long SQL statement. This is connected to the use of the
DbiQExec function.Recommendations
For version 5.1.0.4, consider restricting the length of SQL statements to prevent exploitation until a fix is available.
For version 5.2.0.2, as a temporary workaround, consider disabling the use of the
DbiQExec function in Borland Developer Studio 2006 to minimize the risk of arbitrary code execution.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Borland Developer Studio 2006
Idsql32.Dll