CVE Vulnerabilities

CVE-2006-3854

Published: Aug 17, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.

Affected Software

NameVendorStart VersionEnd Version
Informix_dynamic_database_serverIbm9.40.tc7 (including)9.40.tc7 (including)
Informix_dynamic_database_serverIbm9.40.tc8 (including)9.40.tc8 (including)
Informix_dynamic_database_serverIbm10.00.tc4 (including)10.00.tc4 (including)
Informix_dynamic_database_serverIbm10.00.tc5 (including)10.00.tc5 (including)

References