CVE-2006-3853
NISR02082006A.txt
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 and 10.00 before 10.00.TC3, when running on Windows, allows remote attackers to execute arbitrary code via a long username.
Desbordamiento de búfer en IBMInformix Dynamic Server (IDS) anterior a 9.40.TC7 y 10.00 anterior a 10.00.TC3, cuando se ejecuta en Windows, permite a atacantes remotos ejecutar código de su elección mediante un nombre de usuario largo.
When an Informix server logs on a user it copies the username to a 260 byte stack based buffer without first verifying its length. An attacker can exploit this by overflowing this buffer to overwrite the saved return address on the stack and thus redirect the process' path of execution to a location of their choosing. Versions 9.40.xC6 and below are affected. Versions 10.00.xC2 and below are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-26 CVE Reserved
- 2006-08-08 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdf | X_refsource_misc | |
http://www.osvdb.org/27685 | Vdb Entry | |
http://www.securityfocus.com/archive/1/443133/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/443149/100/0/threaded | Mailing List | |
http://www.vupen.com/english/advisories/2006/3077 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28122 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21301 | 2018-10-17 | |
http://www-1.ibm.com/support/docview.wss?uid=swg21242921 | 2018-10-17 | |
http://www.securityfocus.com/bid/19264 | 2018-10-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.4 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.tc5 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.tc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc1 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc2 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc3 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.uc5 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 9.40.xc7 Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.xc7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 10.0 Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 10.0.xc3 Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.0.xc3" | - |
Affected
|