Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ingress数据库服务器指针覆盖漏洞
Vulnerability Description
Ingres是很多CA产品默认所使用的数据库后端。 CA产品所捆绑Ingres数据库服务器存在"指针覆盖"的漏洞,允许远程攻击者通过在不同时间向通讯服务器进程(iigcc)发送使用某些TCP数据并调用(1)QUinsert或(2)QUremove功能,从而可以实现输入任意代码。
CVSS Information
N/A
Vulnerability Type
N/A