CVE-2008-3357

Ingres <9.1.0 - Privilege Escalation

Title source: llm

Description

Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability."

Scores

EPSS 0.0007
EPSS Percentile 21.5%

Classification

CWE
CWE-426
Status draft

Affected Products (3)

actian/ingres
actian/ingres
actian/ingres

Timeline

Published Aug 05, 2008
Tracked Since Feb 18, 2026