Multiple Vulnerabilities in Sybase Adaptive Server 12.0 and 12.5
Three new buffer-overrun vulnerabilities in Sybase’s Adaptive Server versions 12.5 and 12.0 can grant an attacker complete control over the vulnerable system.
December 1, 2002
Reported November 26, 2002, byApplication Security Inc.
VERSIONS AFFECTED
Sybase Adaptive Server 12.5 and 12.0
DESCRIPTION
Three new buffer-overrun vulnerabilities in Sybase’sAdaptive Server versions 12.5 and 12.0 can grant an attacker complete controlover the vulnerable system. The first vulnerability involves a buffer overflowin the Database Consistency Checker (DBCC) CHECKVERIFY function. The secondvulnerability involves a buffer overflow in the DROP DATABASE function. Thethird vulnerability is a buffer-overflow condition in the stored procedure“xp_freedll”. For more information about these vulnerabilities, see thediscoverer’s Website.
VENDOR RESPONSE
Sybasehas released patches that address these vulnerabilities and recommends thataffected users download the appropriate patch from the company's Web site.
CREDIT
Discoveredby Application Security Inc.
About the Author
You May Also Like