First published: Wed Apr 09 2008(Updated: )
Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) user name, (2) peer name, and possibly unspecified other fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM solidDB | =06.00.1018 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1705 is rated as a high-severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2008-1705, upgrade to a version of IBM solidDB that is later than 06.00.1018.
CVE-2008-1705 can be exploited through format string attacks via user input in fields such as user name and peer name.
IBM solidDB versions 06.00.1018 and earlier are affected by CVE-2008-1705.
CVE-2008-1705 is considered a remote vulnerability because it can be exploited over a network.