First published: Tue Sep 25 2012(Updated: )
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Database Server | =11.50 | |
IBM Informix Dynamic Database Server | =11.50.xc1 | |
IBM Informix Dynamic Database Server | =11.50.xc2 | |
IBM Informix Dynamic Database Server | =11.50.xc3 | |
IBM Informix Dynamic Database Server | =11.50.xc3w1 | |
IBM Informix Dynamic Database Server | =11.50.xc4 | |
IBM Informix Dynamic Database Server | =11.50.xc4w1 | |
IBM Informix Dynamic Database Server | =11.50.xc5 | |
IBM Informix Dynamic Database Server | =11.50.xc5w2 | |
IBM Informix Dynamic Database Server | =11.50.xc5w3 | |
IBM Informix Dynamic Database Server | =11.50.xc5w4 | |
IBM Informix Dynamic Database Server | =11.50.xc6 | |
IBM Informix Dynamic Database Server | =11.50.xc6w1 | |
IBM Informix Dynamic Database Server | =11.50.xc6w2 | |
IBM Informix Dynamic Database Server | =11.50.xc6w3 | |
IBM Informix Dynamic Database Server | =11.50.xc6w4 | |
IBM Informix Dynamic Database Server | =11.50.xc7 | |
IBM Informix Dynamic Database Server | =11.50.xc7w1 | |
IBM Informix Dynamic Database Server | =11.50.xc7w2 | |
IBM Informix Dynamic Database Server | =11.50.xc7w3 | |
IBM Informix Dynamic Database Server | =11.50.xc7w4 | |
IBM Informix Dynamic Database Server | =11.50.xc8 | |
IBM Informix Dynamic Database Server | =11.50.xc8w1 | |
IBM Informix Dynamic Database Server | =11.50.xc8w2 | |
IBM Informix Dynamic Database Server | =11.50.xc8w3 | |
IBM Informix Dynamic Database Server | =11.50.xc8w4 | |
IBM Informix Dynamic Database Server | =11.50.xc9 | |
IBM Informix Dynamic Database Server | =11.50.xc9w1 | |
IBM Informix Dynamic Database Server | =11.70.xc1 | |
IBM Informix Dynamic Database Server | =11.70.xc2 | |
IBM Informix Dynamic Database Server | =11.70.xc3 | |
IBM Informix Dynamic Database Server | =11.70.xc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3334 is considered a high-severity vulnerability due to the potential for remote code execution by authenticated users.
To fix CVE-2012-3334, it is recommended to upgrade IBM Informix Dynamic Server to version 11.50.xC9W2 or higher or 11.70.xC5 or higher.
Remote authenticated users of IBM Informix Dynamic Server versions 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 are affected by CVE-2012-3334.
CVE-2012-3334 is caused by a stack-based buffer overflow that occurs when crafted arguments are processed in a SET COLLATION statement.
Yes, CVE-2012-3334 can be exploited remotely by authenticated users to execute arbitrary code.