Vulnerability Name: | CCN-19976 | ||||||
Published: | 2005-04-05 | ||||||
Updated: | 2005-04-05 | ||||||
Summary: | Sybase Adaptive Server Enterprise (ASE) is vulnerable to a stack-based buffer overflow, caused by a vulnerability in the convert function. A remote attacker with a valid username and password could overflow a buffer and execute arbitrary code on the system to gain complete control over the database server. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: CIAC INFORMATION BULLETIN P-166 Sybase Security Issues in ASE 12.5.3 and Earlier Source: CCN Type: NGSSoftware Insight Security Research Advisory #NISR05042005 Sybase ASE Multiple Security Issues Source: CCN Type: Sybase Web site Adaptive Server Enterprise - Companion TechNote to UCN entitled Urgent from Sybase: Security Issues in ASE 12.5.3 and Earlier. Source: CCN Type: Sybase Adaptive Server Web page Adaptive Server Enterprise Source: XF Type: UNKNOWN sybase-ase-convert-bo(19976) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |