DB: MaxDB WebDBM Server Buffer Overflow

This signature detects attempts to exploit a known vulnerability against MaxDB Web packages. A successful attack can allow an attacker to execute arbitrary code with elevated privileges.

Extended Description

SAP-DB and MaxDB are prone to a remote buffer-overflow vulnerability because these applications fail to perform sufficient bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue may allow remote attackers to execute arbitrary machine code with privileges of the 'wahttp' process. Failed exploit attempts will likely crash the application, denying further service to legitimate users.

Affected Products

Debian linux

Short Name
DB:MYSQL:MAXDB-SERVER-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
Buffer CVE-2006-4305 MaxDB Overflow Server WebDBM bid:19660
Release Date
10/09/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3728
False Positive
Unknown
Vendors

Mysql_ab

Debian

Sap_db

CVSS Score

10.0

Found a potential security threat?