CVE-2007-3336: Critical severity Ingres Database Server vulnerability
Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3336?
CVE-2007-3336 is classified as a critical vulnerability, allowing remote attackers to execute arbitrary code.
How do I fix CVE-2007-3336?
To fix CVE-2007-3336, update the Ingres database server to a patched version provided by the vendor.
Which versions of Ingres are affected by CVE-2007-3336?
CVE-2007-3336 affects Ingres database server versions 2.5, 2.6, 9.0.4, and r3.
What type of attack is associated with CVE-2007-3336?
CVE-2007-3336 is associated with pointer overwrite vulnerabilities that enable arbitrary code execution.
Is remote access required to exploit CVE-2007-3336?
Yes, exploitation of CVE-2007-3336 requires remote access to send specific TCP data.