CVE-2017-1310
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/125569
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg22004930
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | informix_dynamic_server | 12.10 | |
References
- http://www.ibm.com/support/docview.wss?uid=swg22004930
- http://www.securityfocus.com/bid/99309
- http://www.securitytracker.com/id/1038803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125569
- http://www.ibm.com/support/docview.wss?uid=swg22004930
- http://www.securityfocus.com/bid/99309
- http://www.securitytracker.com/id/1038803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125569
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.