Multiple Vulnerabilities in Sybase Adaptive Server 12.0 and 12.5

Three new buffer-overrun vulnerabilities in Sybase’s Adaptive Server versions 12.5 and 12.0 can grant an attacker complete control over the vulnerable system.

Ken Pfeil

December 1, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported November 26, 2002, byApplication Security Inc.

 

 

VERSIONS AFFECTED

 

  • Sybase Adaptive Server 12.5 and 12.0

 

 

DESCRIPTION

 

Three new buffer-overrun vulnerabilities in Sybase’sAdaptive Server versions 12.5 and 12.0 can grant an attacker complete controlover the vulnerable system. The first vulnerability involves a buffer overflowin the Database Consistency Checker (DBCC) CHECKVERIFY function. The secondvulnerability involves a buffer overflow in the DROP DATABASE function. Thethird vulnerability is a buffer-overflow condition in the stored procedure“xp_freedll”. For more information about these vulnerabilities, see thediscoverer’s Website.

 

VENDOR RESPONSE

 

Sybasehas released patches that address these vulnerabilities and recommends thataffected users download the appropriate patch from the company's Web site.

 

CREDIT          

Discoveredby Application Security Inc.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like