First published: Tue Jan 27 2004(Updated: )
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Server | =9.40.uc2 | |
Ibm Informix Extended Parallel Server | =8.40_uc1 | |
IBM Informix Dynamic Server | =9.40.uc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2131 has a high severity due to its ability to allow local users to execute arbitrary code.
To fix CVE-2004-2131, upgrade to a patched version of IBM Informix Dynamic Server or apply relevant security updates.
Local users with DSA privileges on IBM Informix Dynamic Server versions 9.40.xC3 and earlier may be affected by CVE-2004-2131.
CVE-2004-2131 is classified as a stack-based buffer overflow vulnerability.
Yes, CVE-2004-2131 specifically affects IBM Informix Dynamic Server versions 9.40.uc1, 9.40.uc2, and the extended parallel server version 8.40_uc1.