CVE-2004-2131: Buffer Overflow
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2131?
CVE-2004-2131 has a high severity due to its ability to allow local users to execute arbitrary code.
How do I fix CVE-2004-2131?
To fix CVE-2004-2131, upgrade to a patched version of IBM Informix Dynamic Server or apply relevant security updates.
Who is affected by CVE-2004-2131?
Local users with DSA privileges on IBM Informix Dynamic Server versions 9.40.xC3 and earlier may be affected by CVE-2004-2131.
What type of vulnerability is CVE-2004-2131?
CVE-2004-2131 is classified as a stack-based buffer overflow vulnerability.
Is CVE-2004-2131 specific to certain IBM Informix versions?
Yes, CVE-2004-2131 specifically affects IBM Informix Dynamic Server versions 9.40.uc1, 9.40.uc2, and the extended parallel server version 8.40_uc1.