Уязвимость переполнения буфера в функции "SQLDriverConnect" в unixODBC, позволяющая вызвать отказ в обслуживании (DoS) через длинную строку в параметре "FILEDSN"
Описание
Обнаружена уязвимость переполнения буфера в функции SQLDriverConnect в unixODBC. Локальные пользователи могут вызвать отказ в обслуживании (аварийное завершение работы) через длинную строку в параметре FILEDSN.
Примечание: данная проблема может не являться уязвимостью, поскольку возможность установки этого параметра обычно подразумевает, что злоумышленник уже имеет легитимный доступ для вызова отказа в обслуживании или выполнения кода, и, следовательно, проблема не нарушает границы привилегий. Возможны ограниченные сценарии атаки, если параметры командной строки утилиты isql доступны злоумышленнику, хотя вероятно, что в таких случаях будут также обнаружены другие, более серьёзные проблемы. Данная проблема, скорее всего, не нарушает границы привилегий в этом контексте.
Заявление
Red Hat не считает, что аварийное завершение работы клиента с участием пользователя, как в данном случае, является уязвимостью безопасности.
Затронутые версии ПО
- unixODBC 2.0.10
- unixODBC 2.3.1 и более ранние версии
Тип уязвимости
- Аварийное завершение работы (crash)
- Отказ в обслуживании (DoS)
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 4 | unixODBC | Will not fix | ||
| Red Hat Enterprise Linux 5 | unixODBC | Will not fix | ||
| Red Hat Enterprise Linux 5 | unixODBC64 | Will not fix | ||
| Red Hat Enterprise Linux 6 | unixODBC | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS2
Связанные уязвимости
Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue would not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker, although it seems likely that other, more serious issues would also be exposed, and this issue might not cross privilege boundaries in that context.
Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue would not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker, although it seems likely that other, more serious issues would also be exposed, and this issue might not cross privilege boundaries in that context.
Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2 ...
** DISPUTED ** Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue would not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker, although it seems likely that other, more serious issues would also be exposed, and this issue might not cross privilege boundaries in that context.
Уязвимость функции SQLDriverConnect библиотеки ODBC для UNIX UnixODBC, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.3 Low
CVSS2