Vulnerability Description
Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Borland Software | C\+\+ Builder | 5.x |
| Borland Software | C Builder | 2006 |
| Borland Software | Delphi | 5.x |
| Borland Software | Developer Studio | 2006 |
| Borland Software | Idsql32.Dll | 5.1.0.2 |
| Revilloc | Mailserver | All versions |
References
- http://secunia.com/advisories/22570Vendor Advisory
- http://secunia.com/secunia_research/2006-70/advisory/Vendor Advisory
- http://www.securityfocus.com/archive/1/453003/100/0/threaded
- http://www.securityfocus.com/bid/21342
- http://www.vupen.com/english/advisories/2006/4763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30583
- http://secunia.com/advisories/22570Vendor Advisory
- http://secunia.com/secunia_research/2006-70/advisory/Vendor Advisory
- http://www.securityfocus.com/archive/1/453003/100/0/threaded
- http://www.securityfocus.com/bid/21342
- http://www.vupen.com/english/advisories/2006/4763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30583
FAQ
What is CVE-2006-6201?
CVE-2006-6201 is a vulnerability with a CVSS score of 7.5 (HIGH). Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to exec...
How severe is CVE-2006-6201?
CVE-2006-6201 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-6201?
Check the references section above for vendor advisories and patch information. Affected products include: Borland Software C\+\+ Builder, Borland Software C Builder, Borland Software Delphi, Borland Software Developer Studio, Borland Software Idsql32.Dll.