CVE-2004-2131
published 2004-01-27CVE-2004-2131: Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary…
PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
1.43%
69.9th percentile
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | informix_dynamic_server | — | — |
| ibm | informix_dynamic_server | — | — |
| ibm | informix_extended_parallel_server | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
exploitdb·2003-08-08
CVE-2004-2131 IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
---
// source: https://www.securityfocus.com/bid/9512/info
IBM Informix Dynamic Server and IBM Informix Extended Parallel Server have been reported prone to multiple vulnerabilities.
The first issue exists in the onedcu binary. Specifically, when the binary is invoked a predictable temporary file is created. A local attacker may exploit this issue to launch symbolic link style attacks ultimately resulting in elevated privileges.
The second issue that has been reported to exist in the ontape binary. The ontape binary has been reported to be prone to a local stack based buffer overflow vulnerability. Ultimately the attacker may exploit this condition to influence execution flow of the
Exploit-DB
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (1)
exploitdb·2003-08-08
CVE-2004-2131 IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (1)
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (1)
---
source: https://www.securityfocus.com/bid/9512/info
IBM Informix Dynamic Server and IBM Informix Extended Parallel Server have been reported prone to multiple vulnerabilities.
The first issue exists in the onedcu binary. Specifically, when the binary is invoked a predictable temporary file is created. A local attacker may exploit this issue to launch symbolic link style attacks ultimately resulting in elevated privileges.
The second issue that has been reported to exist in the ontape binary. The ontape binary has been reported to be prone to a local stack based buffer overflow vulnerability. Ultimately the attacker may exploit this condition to influence execution flow of the vul
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=107539878804074&w=2http://secunia.com/advisories/10737/http://www-1.ibm.com/support/docview.wss?uid=swg21153336http://www.osvdb.org/3759http://www.securityfocus.com/bid/9512https://exchange.xforce.ibmcloud.com/vulnerabilities/14970http://marc.info/?l=bugtraq&m=107539878804074&w=2http://secunia.com/advisories/10737/http://www-1.ibm.com/support/docview.wss?uid=swg21153336http://www.osvdb.org/3759http://www.securityfocus.com/bid/9512https://exchange.xforce.ibmcloud.com/vulnerabilities/14970
2004-01-27
Published