CVE-2005-0441: Buffer Overflow
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attribvalid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0441?
CVE-2005-0441 has a high severity level due to the presence of multiple stack-based buffer overflows that can allow remote execution of arbitrary code.
How do I fix CVE-2005-0441?
To fix CVE-2005-0441, upgrade to Sybase Adaptive Server Enterprise version 12.5.3 ESD#1 or later.
What are the affected versions in CVE-2005-0441?
CVE-2005-0441 affects Sybase Adaptive Server Enterprise versions 12.x before 12.5.3 ESD#1 and earlier versions.
Who can exploit CVE-2005-0441?
CVE-2005-0441 can be exploited by remote authenticated users who have access to execute specific functions or crafted queries.
What types of functions are involved in CVE-2005-0441?
The functions involved in CVE-2005-0441 include attrib_valid, covert, declare statement, and others that can lead to buffer overflow.