CVE Vulnerabilities

CVE-2024-28930

Integer Underflow (Wrap or Wraparound)

Published: Apr 09, 2024 | Modified: Jan 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Odbc_driver_for_sql_server Microsoft 17.0.1.1 (including) 17.10.6.1 (excluding)
Odbc_driver_for_sql_server Microsoft 18.0.1.1 (including) 18.3.3.1 (excluding)
Sql_server_2019 Microsoft 15.0.2000.5 (including) 15.0.2110.4 (excluding)
Sql_server_2019 Microsoft 15.0.4003.23 (including) 15.0.4360.2 (excluding)
Sql_server_2022 Microsoft 16.0.1000.6 (including) 16.0.1115.1 (excluding)
Sql_server_2022 Microsoft 16.0.4003.1 (including) 16.0.4120.1 (excluding)
Visual_studio_2019 Microsoft 16.0 (including) 16.11.35 (excluding)
Visual_studio_2022 Microsoft 17.4.0 (including) 17.4.18 (excluding)
Visual_studio_2022 Microsoft 17.6.0 (including) 17.6.14 (excluding)
Visual_studio_2022 Microsoft 17.8.0 (including) 17.8.9 (excluding)
Visual_studio_2022 Microsoft 17.9.0 (including) 17.9.6 (excluding)

References