[26460] in bugtraq
TZ Advisores - Buffer Overflow in IBM U2 UniVerse ODBC
daemon@ATHENA.MIT.EDU (Claudio Ortiz Meinberg)
Thu Aug 1 01:48:11 2002
Reply-To: <cmeinberg@sistran.com.br>
From: "Claudio Ortiz Meinberg" <cmeinberg@sistran.com.br>
To: <bugtraq@securityfocus.com>
Date: Wed, 31 Jul 2002 16:28:35 -0300
Message-ID: <000301c238c8$76f30d50$0e040a0a@claudio>
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Systems Affecteds:
All UniVerse versions with UV/ODBC
Explanation:
Trying to make an invalid query the client crashes and make the server slow
with 5sec to 2min lag what could crash the server.
Expoit:
Make a query accessing UV/ODBC (I've used CrystalReports all versions) and
make a valid/invalid link between tables, it will make the server crash, the
line will be locked and the file too.
Resolution:
Just boot the server, it will stop the lag and release the locked line and
file