The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade unixODBCUpgrade unixODBC-debuginfoUpgrade unixODBC-devel | Apr 27, 2020 | Feb 26, 2018 |
| Centos_linux | — | Upgrade unixODBC-develUpgrade unixODBCUpgrade unixODBC-debuginfo | Aug 28, 2019 | Feb 26, 2018 |
| Huawei Euleros 2_0_sp2 | — | — | Dec 4, 2019 | Feb 26, 2018 |
| Huawei Euleros 2_0_sp3 | — | — | Nov 19, 2019 | Feb 26, 2018 |
| Oracle Solaris | — | Upgrade library/unixodbc to version 2.3.6-11.4.2.0.1.1.0 on Solaris 11.4 | Oct 19, 2018 | Feb 26, 2018 |
| Oracle_linux | — | Upgrade unixODBC-develUpgrade unixODBC | Jul 21, 2020 | Feb 27, 2018 |
| Redhat_linux | — | Upgrade unixODBC-debuginfoNo solution existsUpgrade unixODBC-develUpgrade unixODBC | Aug 7, 2019 | Feb 26, 2018 |
| Suse | — | Upgrade unixODBCUpgrade unixODBC-32bitUpgrade unixODBC-devel | May 20, 2018 | Feb 26, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 26, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub