CVE-2004-2490: Buffer Overflow
Published Dec 31, 2004
·Updated
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GLPATH environment variable.
Affected Software
4 affected components
IBM Informix Dynamic Server=9.40.uc2
IBM Informix Extended Parallel Server=8.40_uc1
IBM Informix Dynamic Server=9.40.uc1
IBM Informix Extended Parallel Server=8.40_uc2
Event History
Dec 31, 2004
CVE Published
05:00 AM
Oct 25, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2490?
CVE-2004-2490 has a high severity rating due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2004-2490?
To fix CVE-2004-2490, update your IBM Informix Dynamic Server to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2004-2490?
CVE-2004-2490 affects IBM Informix Dynamic Server 9.40.xC1, 9.40.xC2, and Informix Extended Parallel Server 8.40_uc1 and 8.40_uc2.
4
What kind of attack is possible with CVE-2004-2490?
CVE-2004-2490 allows local users to exploit a buffer overflow vulnerability to execute arbitrary code.
5
Is CVE-2004-2490 related to environment variables?
Yes, CVE-2004-2490 involves a buffer overflow triggered by a long GL_PATH environment variable.