Vulnerability Name: | CVE-2017-1310 (CCN-125569) | ||||||||||||
Assigned: | 2016-11-30 | ||||||||||||
Published: | 2017-06-27 | ||||||||||||
Updated: | 2017-07-07 | ||||||||||||
Summary: | IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1310 Source: CCN Type: IBM Security Bulletin 2004930 (Informix Servers) IBM Informix Dynamic Server is affected by a buffer overflow in Informix function FORMAT_UNITS Source: CONFIRM Type: Patch, Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg22004930 Source: BID Type: Third Party Advisory, VDB Entry 99309 Source: CCN Type: BID-99309 IBM Informix Dynamic Server CVE-2017-1310 Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1038803 Source: MISC Type: VDB Entry, Vendor Advisory https://exchange.xforce.ibmcloud.com/vulnerabilities/125569 Source: XF Type: UNKNOWN ibm-informix-cve20171310-dos(125569) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |