CVE-2011-1145
published 2019-11-14CVE-2011-1145: The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.45%
36.4th percentile
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | unixodbc | < unixodbc 2.2.14p2-3 (bookworm) | unixodbc 2.2.14p2-3 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| unixodbc | unixodbc | <= 2.2.14 | — |
| unixodbc | unixodbc | — | — |
| unixodbc | unixodbc | >= 0 < 2.2.14p2-3 | 2.2.14p2-3 |
| unixodbc | unixodbc | >= 0 < 2.2.14p2-3 | 2.2.14p2-3 |
| unixodbc | unixodbc | >= 0 < 2.2.14p2-3 | 2.2.14p2-3 |
| unixodbc | unixodbc | >= 0 < 2.2.14p2-3 | 2.2.14p2-3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6299-8rx4-fxcv: The SQLDriverConnect() function in unixODBC before 2
ghsa_unreviewed·2022-04-22
CVE-2011-1145 [HIGH] CWE-120 GHSA-6299-8rx4-fxcv: The SQLDriverConnect() function in unixODBC before 2
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
OSV
CVE-2011-1145: The SQLDriverConnect() function in unixODBC before 2
osv·2019-11-14·CVSS 7.8
CVE-2011-1145 [HIGH] CVE-2011-1145: The SQLDriverConnect() function in unixODBC before 2
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Red Hat
unixODBC: possible buffer overrun in SQLDriverConnect()
vendor_redhat·2011-03-09·CVSS 7.8
CVE-2011-1145 [HIGH] unixODBC: possible buffer overrun in SQLDriverConnect()
unixODBC: possible buffer overrun in SQLDriverConnect()
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. We do not currently plan to fix this flaw. If more information becomes available at a future date, we may revisit the issue.
Package: unixODBC (Red Hat Enterprise Linux 4) - Will not fix
Package: unixODBC (Red Hat Enterprise Linux 5) - Will not fix
Package: unixODBC (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2011-1145: unixodbc - The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buff...
vendor_debian·2011·CVSS 7.8
CVE-2011-1145 [HIGH] CVE-2011-1145: unixodbc - The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buff...
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Scope: local
bookworm: resolved (fixed in 2.2.14p2-3)
bullseye: resolved (fixed in 2.2.14p2-3)
forky: resolved (fixed in 2.2.14p2-3)
sid: resolved (fixed in 2.2.14p2-3)
trixie: resolved (fixed in 2.2.14p2-3)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/cve-2011-1145https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-1145https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-1145https://security-tracker.debian.org/tracker/CVE-2011-1145https://access.redhat.com/security/cve/cve-2011-1145https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-1145https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-1145https://security-tracker.debian.org/tracker/CVE-2011-1145
2019-11-14
Published