Vulnerability Name:

CVE-2005-0441 (CCN-19354)

Assigned:2004-12-22
Published:2004-12-22
Updated:2017-07-11
Summary:Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Other
References:Source: BUGTRAQ
Type: Patch, Vendor Advisory
20041222 Sybase ASE 12.5.2 vulnerabilities

Source: CCN
Type: BugTraq Mailing List, Wed Dec 22 2004 - 09:52:50 CST
Sybase ASE 12.5.2 vulnerabilities

Source: MITRE
Type: CNA
CVE-2005-0441

Source: BUGTRAQ
Type: UNKNOWN
20050405 Sybase ASE Multiple Security Issues (#NISR05042005)

Source: CCN
Type: SA13632
Sybase ASE Multiple Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
13632

Source: CCN
Type: SECTRACK ID: 1012662
Sybase Adaptive Server Enterprise Has Three Unspecified High Risk Flaws

Source: CCN
Type: NGSSoftware Insight Security Research Advisory
Sybase ASE Multiple Security Issues

Source: MISC
Type: Vendor Advisory
http://www.ngssoftware.com/advisories/sybase-ase.txt

Source: CCN
Type: OSVDB ID: 15198
Sybase ASE attrib_valid Function Overflow

Source: CCN
Type: OSVDB ID: 15199
Sybase ASE xp_server Malformed Data DoS

Source: CCN
Type: OSVDB ID: 15326
Sybase ASE convert Function Overflow

Source: CCN
Type: OSVDB ID: 15327
Sybase ASE declare Statement Overflow

Source: CCN
Type: OSVDB ID: 15328
Sybase ASE abstract plan Syntax Overflow

Source: BUGTRAQ
Type: Patch, Vendor Advisory
20050321 Details of Sybase ASE bugs withheld

Source: CCN
Type: SecurityFocus Web site
Details of Sybase ASE bugs withheld

Source: BID
Type: Patch, Vendor Advisory
12080

Source: CCN
Type: BID-12080
Sybase Adaptive Server Enterprise Multiple Unspecified Vulnerabilities

Source: CCN
Type: BID-12562
Sybase Adaptive Server Enterprise Unspecified Vulnerability

Source: CCN
Type: BID-13009
Sybase Adaptive Server Enterprise Attrib_Valid Remote Buffer Overflow Vulnerability

Source: CCN
Type: BID-13012
Sybase Adaptive Server Enterprise Install Java Remote Buffer Overflow Vulnerability

Source: CCN
Type: BID-13013
Sybase Adaptive Server Enterprise XP_Server Remote Denial Of Service Vulnerability

Source: CCN
Type: BID-13014
Sybase Adaptive Server Enterprise Query Plan Buffer Overflow Vulnerability

Source: CCN
Type: BID-13015
Sybase Adaptive Server Enterprise Convert Function Remote Buffer Overflow Vulnerability

Source: CCN
Type: BID-13020
Sybase Adaptive Server Enterprise Declare Extension Remote Buffer Overflow Vulnerability

Source: CONFIRM
Type: UNKNOWN
http://www.sybase.com/detail/1,6904,1033894,00.html

Source: CCN
Type: Sybase Inc Web site
Sybase Inc - Urgent Customer Notification: Security Issues in ASE 12.5.3 and Earlier

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.sybase.com/detail?id=1034520

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.sybase.com/detail?id=1034752

Source: CCN
Type: Sybase Adaptive Server Enterprise Web page
Adaptive Server Enterprise

Source: XF
Type: UNKNOWN
sybase-adaptive-multiple-bo(19354)

Source: XF
Type: UNKNOWN
sybase-adaptive-server(19354)

Source: XF
Type: UNKNOWN
sybase-ase-attribvalid-bo(19974)

Source: XF
Type: UNKNOWN
sybase-ase-convert-bo(19976)

Source: XF
Type: UNKNOWN
sybase-ase-declare-bo(19978)

Source: XF
Type: UNKNOWN
sybase-ase-abstract-bo(19979)

Source: XF
Type: UNKNOWN
sybase-ase-install-java-bo(19980)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sybase:adaptive_server_enterprise:11.03.3:*:linux:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:linux:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:sgi:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sybase:adaptive_server_enterprise:11.03.3:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sybase adaptive server enterprise 11.03.3
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5.2
    sybase adaptive server enterprise 12.5.3
    sybase adaptive server enterprise 11.03.3
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5.2
    sybase adaptive server enterprise 12.5.3