Sybase Adaptive Server Remote Password Array Heap Overflow Vulnerability
BID:9080
Info
Sybase Adaptive Server Remote Password Array Heap Overflow Vulnerability
| Bugtraq ID: | 9080 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0327 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery of this vulnerability has been credited to Rapid7, Inc. |
| Vulnerable: |
Sybase Adaptive Server Enterprise 12.5 Win Sybase Adaptive Server Enterprise 12.5 Linux |
| Not Vulnerable: |
Sybase Adaptive Server Enterprise 11.0.3 .3Linux |
Discussion
Sybase Adaptive Server Remote Password Array Heap Overflow Vulnerability
Sybase adaptive server has been reported prone to heap overflow vulnerability. The issue has been reported to present itself when invalid password and servername buffer lengths in a remote password array are passed to the affected server. A heap overflow condition may be triggered, potentially causing heap memory management structures to be corrupted.
It has been reported that an attacker may exploit this condition to trigger a denial of service condition in the affected server.
Sybase adaptive server has been reported prone to heap overflow vulnerability. The issue has been reported to present itself when invalid password and servername buffer lengths in a remote password array are passed to the affected server. A heap overflow condition may be triggered, potentially causing heap memory management structures to be corrupted.
It has been reported that an attacker may exploit this condition to trigger a denial of service condition in the affected server.
Exploit / POC
Sybase Adaptive Server Remote Password Array Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sybase Adaptive Server Remote Password Array Heap Overflow Vulnerability
Solution:
It has been reported that the vendor has released an Electronic Software Distribution (ASE 12.5 ESD#2) to address this issue. Customers are advised to contact the vendor for further details.
Solution:
It has been reported that the vendor has released an Electronic Software Distribution (ASE 12.5 ESD#2) to address this issue. Customers are advised to contact the vendor for further details.
References
Sybase Adaptive Server Remote Password Array Heap Overflow Vulnerability
References:
References: