Vulnerability Description
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 4.0 |
| Redhat | Linux | 4.2 |
References
- http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html
- http://marc.info/?l=bugtraq&m=87602661419259&w=2
- http://www.iss.net/security_center/static/7244.php
- http://www.redhat.com/support/errata/rh42-errata-general.html#db
- http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html
- http://marc.info/?l=bugtraq&m=87602661419259&w=2
- http://www.iss.net/security_center/static/7244.php
- http://www.redhat.com/support/errata/rh42-errata-general.html#db
FAQ
What is CVE-1999-1330?
CVE-1999-1330 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
How severe is CVE-1999-1330?
CVE-1999-1330 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1330?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Redhat Linux.