// For flags

CVE-2006-3862

NISR02082006G.txt

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3 allows attackers to execute arbitrary code via the SQLIDEBUG environment variable (envariable).

Desbordamiento de búfer en IBM Informix Dynamic Server (IDS) 9.40.TC5 hasta 9.40.xC7 y 10.00.TC1 hasta 10.00.xC3 permite a atacantes remotos ejecutar código de su elección a través de la variable de entorno (envariable) SQLIDEBUG.

Informix Dynamic Server is a database developed by IBM. During a security assessment of Informix it was discovered that an overflow could be triggered in a shared library with the SQLIDEBUG environment variable. This can be triggered to gain root privileges by accessing one of the setuid root binaries such as onmode. Versions affected include 9.40.xC6 and earlier and 10.00.xC2, C1.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-07-26 CVE Reserved
  • 2006-08-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Informix Dynamic Server
Search vendor "Ibm" for product "Informix Dynamic Server"
9.40.tc5
Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.tc5"
-
Affected
Ibm
Search vendor "Ibm"
Informix Dynamic Server
Search vendor "Ibm" for product "Informix Dynamic Server"
9.40.uc5
Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.uc5"
-
Affected
Ibm
Search vendor "Ibm"
Informix Dynamic Server
Search vendor "Ibm" for product "Informix Dynamic Server"
9.40.xc5
Search vendor "Ibm" for product "Informix Dynamic Server" and version "9.40.xc5"
-
Affected
Ibm
Search vendor "Ibm"
Informix Dynamic Server
Search vendor "Ibm" for product "Informix Dynamic Server"
10.0.tc1
Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.0.tc1"
-
Affected
Ibm
Search vendor "Ibm"
Informix Dynamic Server
Search vendor "Ibm" for product "Informix Dynamic Server"
10.0.xc1
Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.0.xc1"
-
Affected