Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or sa role privileges to execute arbitrary code via (5) a crafted install java statement.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adaptive_server_enterprise | Sybase | 11.03.3 (including) | 11.03.3 (including) |
Adaptive_server_enterprise | Sybase | 11.5 (including) | 11.5 (including) |
Adaptive_server_enterprise | Sybase | 11.5.1 (including) | 11.5.1 (including) |
Adaptive_server_enterprise | Sybase | 11.9.2 (including) | 11.9.2 (including) |
Adaptive_server_enterprise | Sybase | 12.0 (including) | 12.0 (including) |
Adaptive_server_enterprise | Sybase | 12.0.1 (including) | 12.0.1 (including) |
Adaptive_server_enterprise | Sybase | 12.5 (including) | 12.5 (including) |
Adaptive_server_enterprise | Sybase | 12.5.2 (including) | 12.5.2 (including) |
Adaptive_server_enterprise | Sybase | 12.5.3 (including) | 12.5.3 (including) |