Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Informix_dynamic_server | Ibm | 9.40.uc1 (including) | 9.40.uc1 (including) |
Informix_dynamic_server | Ibm | 9.40.uc2 (including) | 9.40.uc2 (including) |