Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2008-08-05 19:41
Updated : 2025-04-09 00:30
NVD link : CVE-2008-3389
Mitre link : CVE-2008-3389
CVE.ORG link : CVE-2008-3389
JSON object : View
Products Affected
hp
- hp-ux
linux
- linux_kernel
ingres
- ingres
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer