Integer signedness error in the SQLConnectW function in an ODBC...
Vulnerability Description
Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-0026
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2011/0075
- http://www.securityfocus.com/bid/45695
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-002
- http://osvdb.org/70443
- http://www.securitytracker.com/id?1024947
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12333
- http://www.zerodayinitiative.com/advisories/ZDI-11-001/
- http://secunia.com/advisories/42804
- http://www.us-cert.gov/cas/techalerts/TA11-011A.html
- http://support.avaya.com/css/P8/documents/100124846
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.