First published: Tue Aug 08 2006(Updated: )
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3 allows attackers to execute arbitrary code via the SQLIDEBUG environment variable (envariable).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix | =9.40.tc5 | |
IBM Informix | =9.40.xc5 | |
IBM Informix | =10.0.xc1 | |
IBM Informix | =10.0.tc1 | |
IBM Informix | =9.40.uc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3862 is considered a critical vulnerability due to its ability to allow attackers to execute arbitrary code remotely.
To fix CVE-2006-3862, upgrade IBM Informix Dynamic Server to a version that is not affected by this vulnerability, specifically 9.40.xC8 or later, or 10.00.xC4 or later.
CVE-2006-3862 affects IBM Informix Dynamic Server versions 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3.
Exploiting CVE-2006-3862 can lead to remote code execution, allowing attackers to gain unauthorized control of the database server.
CVE-2006-3862 occurs due to a buffer overflow triggered by the SQLIDEBUG environment variable processing in IBM Informix Dynamic Server.