Out-of-bounds write in unixODBC - CVE-2024-1013

 

Out-of-bounds write in unixODBC - CVE-2024-1013

Published: March 28, 2024


Vulnerability identifier: #VU87903
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-1013
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing untrusted input on 64-bit systems. A local user can trigger an out-of-bounds write and perform a denial of service (DoS) attack.


Affected software

unixODBC
Amazon Linux AMI
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Ubuntu
openEuler
Anolis OS
DataStage on Cloud Pak for Data
unixodbc (Ubuntu package)
libodbc1 (Ubuntu package)
unixODBC
unixODBC-devel
unixODBC-debugsource
unixODBC-debuginfo
libodbc2 (Ubuntu package)
libodbc2
libodbc2-debuginfo
libodbc2-32bit
unixODBC-debuginfo-32bit
libodbc2-debuginfo-32bit
unixODBC-32bit
unixODBC-doc
Dell Secure Connect Gateway

How to mitigate CVE-2024-1013

Install updates from vendor's website.

DataStage on Cloud Pak for Data - update to 5.2.1
unixodbc (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.6-0.1ubuntu0.1, 2.3.9-5ubuntu0.1, 2.3.12-1ubuntu0.23.10.1, 2.3.12-1ubuntu0.24.04.1
libodbc1 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.6-0.1ubuntu0.1, 2.3.9-5ubuntu0.1
unixODBC - addressed in versions 2.3.7-3.h1, 2.3.9-4
unixODBC-devel - addressed in versions 2.3.7-3.h1, 2.3.9-4
unixODBC-debugsource - addressed in versions 2.3.7-3.h1, 2.3.9-4
unixODBC-debuginfo - addressed in versions 2.3.7-3.h1, 2.3.9-4
unixODBC - update to 2.3.9-3
libodbc2 (Ubuntu package) - addressed in versions 2.3.9-5ubuntu0.1, 2.3.12-1ubuntu0.23.10.1, 2.3.12-1ubuntu0.24.04.1
unixODBC-devel - update to 2.3.9-7.16.1
unixODBC-debugsource - update to 2.3.9-7.16.1
unixODBC-debuginfo - update to 2.3.9-7.16.1
unixODBC - update to 2.3.9-7.16.1
libodbc2 - update to 2.3.9-7.16.1
libodbc2-debuginfo - update to 2.3.9-7.16.1
libodbc2-32bit - update to 2.3.9-7.16.1
unixODBC-debuginfo-32bit - update to 2.3.9-7.16.1
libodbc2-debuginfo-32bit - update to 2.3.9-7.16.1
unixODBC-32bit - update to 2.3.9-7.16.1
unixODBC - update to 2.3.11-4
unixODBC-devel - update to 2.3.11-4
unixODBC-doc - update to 2.3.11-4
Dell Secure Connect Gateway - update to 5.26.00.18

External References

Related Security Bulletins