Candidate: CVE-2011-1145 PublicDate: 2019-11-14 02:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1145 Description: The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. Ubuntu-Description: Notes: jdstrand> should be denial of service only due to stack-protector Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Tags_unixodbc: stack-protector Patches_unixodbc: upstream: http://unixodbc.svn.sourceforge.net/viewvc/unixodbc/trunk/DriverManager/SQLDriverConnect.c?r1=23&r2=27&view=patch upstream_unixodbc: released (2.2.14p2-3) hardy_unixodbc: ignored (reached end-of-life) lucid_unixodbc: ignored (reached end-of-life) maverick_unixodbc: ignored (reached end-of-life) natty_unixodbc: ignored (reached end-of-life) oneiric_unixodbc: ignored (reached end-of-life) precise_unixodbc: not-affected (2.2.14p2-5ubuntu2) quantal_unixodbc: not-affected (2.2.14p2-5ubuntu2) raring_unixodbc: not-affected (2.2.14p2-5ubuntu2) saucy_unixodbc: not-affected (2.2.14p2-5ubuntu2) trusty_unixodbc: not-affected (2.2.14p2-5ubuntu2) trusty/esm_unixodbc: not-affected (2.2.14p2-5ubuntu2) utopic_unixodbc: not-affected (2.2.14p2-5ubuntu2) vivid_unixodbc: not-affected (2.2.14p2-5ubuntu2) devel_unixodbc: not-affected (2.2.14p2-5ubuntu2)