First published: Fri Dec 31 2004(Updated: )
Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Database Server | =9.40.uc1 | |
IBM Informix Dynamic Database Server | =9.40.uc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2489 has a high severity level as it allows local users to execute arbitrary code.
To fix CVE-2004-2489, upgrade IBM Informix Dynamic Server to version 9.40.xC3 or later.
CVE-2004-2489 affects local users of IBM Informix Dynamic Server versions 9.40.uc1 and 9.40.uc2.
Systems running IBM Informix Dynamic Server prior to version 9.40.xC3 are vulnerable to CVE-2004-2489.
CVE-2004-2489 is a format string vulnerability that can be exploited through a modified INFORMIXDIR environment variable.