CVE Database
/

CVE-2006-3857

Back to search

CVE-2006-3857

Published: Aug 8, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in IBM Informix Dynamic Server (IDS) before 9.40.TC6 and 10.00 before 10.00.TC3 allow remote authenticated users to execute arbitrary code via (1) the getname function, as used by (a) _sq_remview, (b) _sq_remproc, (c) _sq_remperms, (d) _sq_distfetch, and (e) _sq_dcatalog; and the (2) SET DEBUG FILE, (3) IFX_FILE_TO_FILE, (4) FILETOCLOB, (5) LOTOFILE, and (6) DBINFO functions (product defect IDs 171649, 171367, 171387, 171391, 171906, 172179).

VendorProductVersions

n/a

n/a

affected
n/a

References

27693
vdb-entry
x_refsource_OSVDB
informix-lotofile-bo(28119)
vdb-entry
x_refsource_XF
27683
vdb-entry
x_refsource_OSVDB
27687
vdb-entry
x_refsource_OSVDB
informix-getname-bo(28127)
vdb-entry
x_refsource_XF
27681
vdb-entry
x_refsource_OSVDB
informix-dbinfo-bo(28118)
vdb-entry
x_refsource_XF
informix-setdebugfile-bo(28126)
vdb-entry
x_refsource_XF
informix-ifxfiletofile-bo(28157)
vdb-entry
x_refsource_XF
21301
third-party-advisory
x_refsource_SECUNIA
19264
vdb-entry
x_refsource_BID
ADV-2006-3077
vdb-entry
x_refsource_VUPEN
27688
vdb-entry
x_refsource_OSVDB
27682
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now