Vulnerability Name:

CVE-2005-0942 (CCN-19981)

Assigned:2005-04-05
Published:2005-04-05
Updated:2017-07-11
Summary:The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: BUGTRAQ
Type: Patch
20041222 Sybase ASE 12.5.2 vulnerabilities

Source: MITRE
Type: CNA
CVE-2005-0942

Source: BUGTRAQ
Type: UNKNOWN
20050405 Sybase ASE Multiple Security Issues (#NISR05042005)

Source: CCN
Type: SA13632
Sybase ASE Multiple Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
13632

Source: CCN
Type: CIAC INFORMATION BULLETIN P-166
Sybase Security Issues in ASE 12.5.3 and Earlier

Source: CCN
Type: NGSSoftware Insight Security Research Advisory #NISR05042005
Sybase ASE Multiple Security Issues

Source: MISC
Type: Patch, Vendor Advisory
http://www.ngssoftware.com/advisories/sybase-ase.txt

Source: CCN
Type: OSVDB ID: 12563
Sybase ASE "install java" Overflow

Source: BUGTRAQ
Type: Vendor Advisory
20050321 Details of Sybase ASE bugs withheld

Source: BID
Type: Patch
12080

Source: CCN
Type: BID-12080
Sybase Adaptive Server Enterprise Multiple Unspecified Vulnerabilities

Source: CONFIRM
Type: UNKNOWN
http://www.sybase.com/detail/1,6904,1033894,00.html

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.sybase.com/detail?id=1034520

Source: CCN
Type: Sybase Web site
Adaptive Server Enterprise - Companion TechNote to UCN entitled Urgent from Sybase: Security Issues in ASE 12.5.3 and Earlier.

Source: CONFIRM
Type: Vendor Advisory
http://www.sybase.com/detail?id=1034752

Source: CCN
Type: Sybase Adaptive Server Web page
Adaptive Server Enterprise

Source: XF
Type: UNKNOWN
sybase-adaptive-server(19354)

Source: XF
Type: UNKNOWN
sybase-ase-xpserver-dos(19981)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sybase:adaptive_server_enterprise:11.03.3:*:linux:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:digital_unix:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:hp:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:linux:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:sgi:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:sun:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:win:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sybase:adaptive_server_enterprise:11.03.3:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:11.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sybase:adaptive_server_enterprise:12.5.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sybase adaptive server enterprise 11.03.3
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5.2
    sybase adaptive server enterprise 12.5.3
    sybase adaptive server enterprise 11.03.3
    sybase adaptive server enterprise 11.5
    sybase adaptive server enterprise 11.5.1
    sybase adaptive server enterprise 11.9.2
    sybase adaptive server enterprise 12.0
    sybase adaptive server enterprise 12.0.1
    sybase adaptive server enterprise 12.5
    sybase adaptive server enterprise 12.5.2
    sybase adaptive server enterprise 12.5.3