#VU45318 Stack-based buffer overflow in Informix Dynamic Server - CVE-2011-1033
Published: February 15, 2011 / Updated: August 11, 2020
Informix Dynamic Server
IBM Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-ibm
- http://secunia.com/advisories/43212
- http://securityreason.com/securityalert/8078
- http://www.securityfocus.com/archive/1/516250/100/0/threaded
- http://www.securityfocus.com/bid/46230
- http://www.vupen.com/english/advisories/2011/0309
- http://zerodayinitiative.com/advisories/ZDI-11-050/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65209