First published: Thu Aug 17 2006(Updated: )
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Database server | =10.00.tc5 | |
IBM Informix Dynamic Database server | =9.40.tc7 | |
IBM Informix Dynamic Database server | =10.00.tc4 | |
IBM Informix Dynamic Database server | =9.40.tc8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3854 is considered a high severity vulnerability due to its potential for remote code execution.
CVE-2006-3854 occurs when a remote attacker sends a long username that causes a buffer overflow in the Informix Dynamic Server.
CVE-2006-3854 affects IBM Informix Dynamic Server versions 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5.
To fix CVE-2006-3854, apply the latest security patches provided by IBM for the affected Informix Dynamic Server versions.
Mitigation for CVE-2006-3854 includes implementing strict input validation and limiting username length to prevent buffer overflow.