First published: Sat Dec 08 2012(Updated: )
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Server | =11.50 | |
IBM Informix Dynamic Server | =11.50.xc1 | |
IBM Informix Dynamic Server | =11.50.xc2 | |
IBM Informix Dynamic Server | =11.50.xc3 | |
IBM Informix Dynamic Server | =11.50.xc3w1 | |
IBM Informix Dynamic Server | =11.50.xc4 | |
IBM Informix Dynamic Server | =11.50.xc4w1 | |
IBM Informix Dynamic Server | =11.50.xc5 | |
IBM Informix Dynamic Server | =11.50.xc5w2 | |
IBM Informix Dynamic Server | =11.50.xc5w3 | |
IBM Informix Dynamic Server | =11.50.xc5w4 | |
IBM Informix Dynamic Server | =11.50.xc6 | |
IBM Informix Dynamic Server | =11.50.xc6w1 | |
IBM Informix Dynamic Server | =11.50.xc6w2 | |
IBM Informix Dynamic Server | =11.50.xc6w3 | |
IBM Informix Dynamic Server | =11.50.xc6w4 | |
IBM Informix Dynamic Server | =11.50.xc7 | |
IBM Informix Dynamic Server | =11.50.xc7w1 | |
IBM Informix Dynamic Server | =11.50.xc7w2 | |
IBM Informix Dynamic Server | =11.50.xc7w3 | |
IBM Informix Dynamic Server | =11.50.xc7w4 | |
IBM Informix Dynamic Server | =11.50.xc8 | |
IBM Informix Dynamic Server | =11.50.xc8w1 | |
IBM Informix Dynamic Server | =11.50.xc8w2 | |
IBM Informix Dynamic Server | =11.50.xc8w3 | |
IBM Informix Dynamic Server | =11.50.xc8w4 | |
IBM Informix Dynamic Server | =11.50.xc9 | |
IBM Informix Dynamic Server | =11.70.xc1 | |
IBM Informix Dynamic Server | =11.70.xc2 | |
IBM Informix Dynamic Server | =11.70.xc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4857 has a critical severity level due to its potential to allow remote code execution.
To fix CVE-2012-4857, upgrade IBM Informix to a patched version that addresses the buffer overflow vulnerability.
CVE-2012-4857 affects IBM Informix Dynamic Server versions 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7.
CVE-2012-4857 is classified as a buffer overflow vulnerability that can be exploited by remote authenticated users.
Potential impacts of CVE-2012-4857 include unauthorized remote code execution and potential compromise of the affected system.