Description
Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
References (10)
Core 10
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0075
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/45695
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-002
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/70443
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1024947
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12333
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-11-001/
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42804
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-011A.html
Vendor Advisory x_refsource_confirm
http://support.avaya.com/css/P8/documents/100124846
Scores
EPSS
0.3440
EPSS Percentile
98.3%
Details
CWE
CWE-189
Status
published
Products (2)
microsoft/data_access_components
2.8 sp1 (2 CPE variants)
microsoft/windows_data_access_components
6.0
Published
Jan 12, 2011
Tracked Since
Feb 18, 2026