Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) user name, (2) peer name, and possibly unspecified other fields.
References
Configurations
History
21 Nov 2024, 00:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://aluigi.altervista.org/adv/soliduro-adv.txt - | |
References | () http://aluigi.org/poc/soliduro.zip - Exploit | |
References | () http://secunia.com/advisories/29512 - | |
References | () http://securitytracker.com/id?1019721 - | |
References | () http://www.securityfocus.com/archive/1/490129/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/28468 - | |
References | () http://www.vupen.com/english/advisories/2008/1038 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/41485 - |
Information
Published : 2008-04-09 19:05
Updated : 2024-11-21 00:45
NVD link : CVE-2008-1705
Mitre link : CVE-2008-1705
CVE.ORG link : CVE-2008-1705
JSON object : View
Products Affected
ibm
- soliddb
CWE
CWE-134
Use of Externally-Controlled Format String