CVE-2011-0026: Buffer Overflow
Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0026?
CVE-2011-0026 is rated as critical due to the potential for remote code execution.
How do I fix CVE-2011-0026?
To fix CVE-2011-0026, apply the relevant patches provided by Microsoft for Microsoft Data Access Components.
What versions are affected by CVE-2011-0026?
CVE-2011-0026 affects Microsoft Data Access Components versions 2.8 SP1, 2.8 SP2, and Windows Data Access Components version 6.0.
Can CVE-2011-0026 be exploited remotely?
Yes, CVE-2011-0026 can be exploited remotely by attackers via a long string in the Data Source Name.
What are the potential impacts of CVE-2011-0026?
The potential impacts of CVE-2011-0026 include arbitrary code execution, which can lead to system compromise.