CVE-1999-1330 Information

Description

The snprintf function in the db library 1.85.4 ignores the size parameter which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.

Reference

http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html http://marc.info/?l=bugtraq&m=87602661419259&w=2 http://www.iss.net/security_center/static/7244.php http://www.redhat.com/support/errata/rh42-errata-general.htmldb

Share on: