Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 











Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Vigil@nce - IBM Informix Dynamic Server: privilege elevation via COLLATION

October 2012 by Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

A local attacker can use the SET COLLATION command of IBM Informix
Dynamic Server, in order to generate a buffer overflow, and to
execute code with privileges of the service.

Impacted products: Informix Dynamic Server

Severity: 2/4

Creation date: 25/09/2012

DESCRIPTION OF THE VULNERABILITY

The "SET COLLATION" SQL command is used to define the sorting
order of characters (most of the times, it depends on the locale).
For example :
SET COLLATION en_us.8859-1

However, if the parameter is too long, an overflow occurs.

A local attacker can therefore use the SET COLLATION command of
IBM Informix Dynamic Server, in order to generate a buffer
overflow, and to execute code with privileges of the service.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/IBM-Informix-Dynamic-Server-privilege-elevation-via-COLLATION-11976


See previous articles

    

See next articles












Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts