Vulnerabilities > CVE-2004-2489 - Unspecified vulnerability in IBM Informix Dynamic Server 9.40.Uc1/9.40.Uc2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://marc.info/?l=bugtraq&m=107524391217364&w=2
- http://marc.info/?l=bugtraq&m=107524391217364&w=2
- http://secunia.com/advisories/10737
- http://secunia.com/advisories/10737
- http://www.osvdb.org/3757
- http://www.osvdb.org/3757
- http://www.securityfocus.com/bid/9511
- http://www.securityfocus.com/bid/9511
- http://www-1.ibm.com/support/docview.wss?uid=swg21153336
- http://www-1.ibm.com/support/docview.wss?uid=swg21153336
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14967