PT-2008-2386 · Ibm · Ibm Informix Dynamic Server
Published
2008-02-13
·
Updated
2019-08-01
·
CVE-2008-0768
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Informix Dynamic Server (IDS) versions 10.00.xC8 and earlier
Informix Dynamic Server (IDS) versions 11.10.xC2 and earlier
Description
The issue concerns multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS). This allows attackers to execute arbitrary code via crafted XDR requests.
Recommendations
For Informix Dynamic Server (IDS) versions 10.00.xC8 and earlier, update to a version later than 10.00.xC8 to resolve the issue.
For Informix Dynamic Server (IDS) versions 11.10.xC2 and earlier, update to a version later than 11.10.xC2 to resolve the issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Informix Dynamic Server