Integer overflow in Borland... CVE-2008-2559 CNNVD-200806-102

7.5 AV AC AU C I A
发布: 2008-06-05
修订: 2017-08-08

Borland InterBase是跨平台的高性能商业数据库。 Borland Interbase数据库在处理发送给默认TCP 3050端口的畸形报文时存在整数溢出漏洞,最终可能导致栈溢出,允许以系统权限执行任意指令。 Solaris版本中的漏洞代码段: /----------- inet_accept_connection+0x164: srl %o5, 0x10, %o7 inet_accept_connection+0x168: ld[%l0 + 0xcc], %l1 inet_accept_connection+0x16c: sth %o7, [%l1 + 8] inet_accept_connection+0x170: ba+0x3a0 <inet_accept_connection+0x510> inet_accept_connection+0x174: ld[%fp - 0x8c], %g2 inet_accept_connection+0x178: ld[%fp - 0x88], %g3 inet_accept_connection+0x17c: add %fp, -0x84, %g2 inet_accept_connection+0x180: st%g2, [%fp - 0x90] inet_accept_connection+0x184: ldsb[%g3], %g4 inet_accept_connection+0x188: st%g4, [%fp - 0xa0] inet_accept_connection+0x18c: ld[%fp - 0x88], %o5 inet_accept_connection+0x190: add %o5, 1, %o7 inet_accept_connection+0x194: st%o7, [%fp - 0x88] inet_accept_connection+0x198: ld[%fp - 0xa0], %o4 inet_accept_connection+0x19c: st%o4, [%fp - 0x304] inet_accept_connection+0x1a0: ld[%fp - 0x304], %l0 inet_accept_connection+0x1a4: st%l0, [%fp -...

0%
暂无可用Exp或PoC
当前有1条受影响产品信息