An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade unixODBC-debuginfoUpgrade unixODBC-develUpgrade unixODBC | Jun 13, 2024 | Mar 18, 2024 |
| Amazon_linux_2023 | — | Upgrade unixODBCUpgrade unixODBC-debuginfoUpgrade unixODBC-debugsourceUpgrade unixODBC-devel | Feb 17, 2025 | Mar 18, 2024 |
| Debian | — | No solution exists | May 15, 2025 | Mar 18, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 18, 2024 |
| Suse | — | Upgrade libodbc2Upgrade unixODBCUpgrade unixODBC-develUpgrade libodbc2-32bitUpgrade unixODBC-32bit | Aug 21, 2024 | Mar 18, 2024 |
| Ubuntu | — | Upgrade unixodbc (Ubuntu Pro)Upgrade libodbc1Upgrade unixodbcUpgrade libodbc1 (Ubuntu Pro) | Mar 28, 2024 | Mar 18, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub