Sign in
CVE-2003-0939
CVE-2003-0939
Description
eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256 byte segment to the niserver (aka serv.exe) process on TCP port 7269, which prevents the server from NULL terminating the string and leads to a buffer overflow.
Impact
CVSS v2 : 7.5 HIGH
Type
NVD-CWE-Other
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:N/C:P/I:P/A:P
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
http://www.atstake.com/research/advisories/2003/a111703-1.txt
http://www.sapdb.org/7.4/new_relinfo.txt
FAQ
Terms of service
Privacy policy