Sybase Adaptive Server Anywhere Database Engine Buffer Overflow Vulnerability

BID:2572

Info

Sybase Adaptive Server Anywhere Database Engine Buffer Overflow Vulnerability

Bugtraq ID: 2572
Class: Boundary Condition Error
CVE: CVE-2001-0599
Remote: Yes
Local: No
Published: Apr 11 2001 12:00AM
Updated: Jul 11 2009 06:06AM
Credit: Discovered by Peter Gründl <[email protected]> and posted to Bugtraq on April 11, 2001.
Vulnerable: Sybase Adaptive Server Anywhere Database Engine 6.0.3 .2747
+ Symantec Ghost Corporate Edition 6.5
Not Vulnerable:

Discussion

Sybase Adaptive Server Anywhere Database Engine Buffer Overflow Vulnerability

The Sybase Adaptive Server Anywhere Database Engine that is shipped with Symantec Ghost is susceptible to a buffer overflow attack via TCP port 2638. An unauthorized remote attacker may connect to port 2638, the port which the database engine listens on, and supply a buffer of approximately 45 kilobytes. Depending on the data entered, a denial of service attack could be launched or arbitrary code could be executed on the system Ghost resides.

Exploit / POC

Sybase Adaptive Server Anywhere Database Engine Buffer Overflow Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] &lt;mailto:[email protected]&gt;.

Solution / Fix

Sybase Adaptive Server Anywhere Database Engine Buffer Overflow Vulnerability

Solution:
Symantec has rectified this issue with the release of Ghost version 7.0. Upgrades to 7.0 are free for those who purchased Upgrade Insurance as part of their license. Direct all inquiries to:

http://www.symantec.com/ghost
and/or
http://www.binaryresearch.net

References

Sybase Adaptive Server Anywhere Database Engine Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report