Vulnerability Name: CVE-2005-0441 (CCN-19354) Assigned: 2004-12-22 Published: 2004-12-22 Updated: 2017-07-11 Summary: Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement. CVSS v3 Severity: 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C )6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Other References: Source: BUGTRAQ Type: Patch, Vendor Advisory20041222 Sybase ASE 12.5.2 vulnerabilities Source: CCN Type: BugTraq Mailing List, Wed Dec 22 2004 - 09:52:50 CSTSybase ASE 12.5.2 vulnerabilities Source: MITRE Type: CNACVE-2005-0441 Source: BUGTRAQ Type: UNKNOWN20050405 Sybase ASE Multiple Security Issues (#NISR05042005) Source: CCN Type: SA13632Sybase ASE Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory13632 Source: CCN Type: SECTRACK ID: 1012662Sybase Adaptive Server Enterprise Has Three Unspecified High Risk Flaws Source: CCN Type: NGSSoftware Insight Security Research AdvisorySybase ASE Multiple Security Issues Source: MISC Type: Vendor Advisoryhttp://www.ngssoftware.com/advisories/sybase-ase.txt Source: CCN Type: OSVDB ID: 15198Sybase ASE attrib_valid Function Overflow Source: CCN Type: OSVDB ID: 15199Sybase ASE xp_server Malformed Data DoS Source: CCN Type: OSVDB ID: 15326Sybase ASE convert Function Overflow Source: CCN Type: OSVDB ID: 15327Sybase ASE declare Statement Overflow Source: CCN Type: OSVDB ID: 15328Sybase ASE abstract plan Syntax Overflow Source: BUGTRAQ Type: Patch, Vendor Advisory20050321 Details of Sybase ASE bugs withheld Source: CCN Type: SecurityFocus Web siteDetails of Sybase ASE bugs withheld Source: BID Type: Patch, Vendor Advisory12080 Source: CCN Type: BID-12080Sybase Adaptive Server Enterprise Multiple Unspecified Vulnerabilities Source: CCN Type: BID-12562Sybase Adaptive Server Enterprise Unspecified Vulnerability Source: CCN Type: BID-13009Sybase Adaptive Server Enterprise Attrib_Valid Remote Buffer Overflow Vulnerability Source: CCN Type: BID-13012Sybase Adaptive Server Enterprise Install Java Remote Buffer Overflow Vulnerability Source: CCN Type: BID-13013Sybase Adaptive Server Enterprise XP_Server Remote Denial Of Service Vulnerability Source: CCN Type: BID-13014Sybase Adaptive Server Enterprise Query Plan Buffer Overflow Vulnerability Source: CCN Type: BID-13015Sybase Adaptive Server Enterprise Convert Function Remote Buffer Overflow Vulnerability Source: CCN Type: BID-13020Sybase Adaptive Server Enterprise Declare Extension Remote Buffer Overflow Vulnerability Source: CONFIRM Type: UNKNOWNhttp://www.sybase.com/detail/1,6904,1033894,00.html Source: CCN Type: Sybase Inc Web siteSybase Inc - Urgent Customer Notification: Security Issues in ASE 12.5.3 and Earlier Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.sybase.com/detail?id=1034520 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.sybase.com/detail?id=1034752 Source: CCN Type: Sybase Adaptive Server Enterprise Web pageAdaptive Server Enterprise Source: XF Type: UNKNOWNsybase-adaptive-multiple-bo(19354) Source: XF Type: UNKNOWNsybase-adaptive-server(19354) Source: XF Type: UNKNOWNsybase-ase-attribvalid-bo(19974) Source: XF Type: UNKNOWNsybase-ase-convert-bo(19976) Source: XF Type: UNKNOWNsybase-ase-declare-bo(19978) Source: XF Type: UNKNOWNsybase-ase-abstract-bo(19979) Source: XF Type: UNKNOWNsybase-ase-install-java-bo(19980) Vulnerable Configuration: Configuration 1 :cpe:/a:sybase:adaptive_server_enterprise:11.03.3:*:linux:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:digital_unix:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:hp:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:sun:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:win:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:digital_unix:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:hp:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:sun:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:win:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:digital_unix:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:hp:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:sun:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:win:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:digital_unix:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:hp:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:sun:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:win:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:digital_unix:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:hp:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:sun:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:win:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:digital_unix:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:hp:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:linux:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:sgi:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:sun:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:win:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5.2:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5.3:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:sybase:adaptive_server_enterprise:11.03.3:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5.2:*:*:*:*:*:*:* OR cpe:/a:sybase:adaptive_server_enterprise:12.5.3:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
sybase adaptive server enterprise 11.03.3
sybase adaptive server enterprise 11.5
sybase adaptive server enterprise 11.5
sybase adaptive server enterprise 11.5
sybase adaptive server enterprise 11.5
sybase adaptive server enterprise 11.5.1
sybase adaptive server enterprise 11.5.1
sybase adaptive server enterprise 11.5.1
sybase adaptive server enterprise 11.5.1
sybase adaptive server enterprise 11.9.2
sybase adaptive server enterprise 11.9.2
sybase adaptive server enterprise 11.9.2
sybase adaptive server enterprise 11.9.2
sybase adaptive server enterprise 12.0
sybase adaptive server enterprise 12.0
sybase adaptive server enterprise 12.0
sybase adaptive server enterprise 12.0
sybase adaptive server enterprise 12.0.1
sybase adaptive server enterprise 12.0.1
sybase adaptive server enterprise 12.0.1
sybase adaptive server enterprise 12.0.1
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5.2
sybase adaptive server enterprise 12.5.3
sybase adaptive server enterprise 11.03.3
sybase adaptive server enterprise 11.5
sybase adaptive server enterprise 11.5.1
sybase adaptive server enterprise 11.9.2
sybase adaptive server enterprise 12.0
sybase adaptive server enterprise 12.0.1
sybase adaptive server enterprise 12.5
sybase adaptive server enterprise 12.5.2
sybase adaptive server enterprise 12.5.3