Immune Systems:
* IBM Informix version 7.31
* IBM Informix version 9.40
SQL query execution privileges are required to exploit this vulnerability.
The specific flaw exists when processing the arguments to the DBINFO keyword in a SQL query. User-supplied data is copied into a stack-based buffer without proper bounds checking resulting in an exploitable overflow. Exploitation can result in arbitrary code execution under the context of the database server.
Disclosure Timeline:
2008-08-26 - Vulnerability reported to vendor
2010-10-18 - Coordinated public release of advisory