CVE Database
/

CVE-2008-3389

Back to search

CVE-2008-3389

Published: Aug 5, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.

VendorProductVersions

n/a

n/a

affected
n/a

References

1020615
vdb-entry
x_refsource_SECTRACK
ADV-2008-2292
vdb-entry
x_refsource_VUPEN
31398
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2313
vdb-entry
x_refsource_VUPEN
31357
third-party-advisory
x_refsource_SECUNIA
ingres-libbecompat-bo(44179)
vdb-entry
x_refsource_XF
30512
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now