Progress sqlcpp Local Buffer Overflow Vulnerability
BID:4402
Info
Progress sqlcpp Local Buffer Overflow Vulnerability
| Bugtraq ID: | 4402 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 22 2002 12:00AM |
| Updated: | Mar 22 2002 12:00AM |
| Credit: | Discovered by KF <[email protected]>. |
| Vulnerable: |
Progress Database 9.1 C Progress Database 9.1 B |
| Not Vulnerable: |
Progress Database 9.1 D |
Discussion
Progress sqlcpp Local Buffer Overflow Vulnerability
Progress is a commercial database for Microsoft Windows and Unix systems.
A buffer overflow has been reported in the sqlcpp program included with Progress, used as a SQL preprocessor. Execution of arbitrary code is possible.
This issue has been reported to affect Unix systems. This vulnerability may also exist under Windows, this has not however been confirmed.
Progress is a commercial database for Microsoft Windows and Unix systems.
A buffer overflow has been reported in the sqlcpp program included with Progress, used as a SQL preprocessor. Execution of arbitrary code is possible.
This issue has been reported to affect Unix systems. This vulnerability may also exist under Windows, this has not however been confirmed.
Exploit / POC
Progress sqlcpp Local Buffer Overflow Vulnerability
An exploit has been provided by The Itch / Promisc (http://www.promisc.org):
An exploit has been provided by The Itch / Promisc (http://www.promisc.org):
Solution / Fix
Progress sqlcpp Local Buffer Overflow Vulnerability
Solution:
This issue has been reported fixed in version 9.1D, and patched in 9.1C.
Solution:
This issue has been reported fixed in version 9.1D, and patched in 9.1C.
References
Progress sqlcpp Local Buffer Overflow Vulnerability
References:
References:
- Progress Database Product Page (Progress)
- Progress Software suid overflows again. (KF
)