Unrated severityNVD Advisory· Published Aug 5, 2008· Updated Apr 23, 2026
CVE-2008-3389
CVE-2008-3389
Description
Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/31357nvdThird Party Advisory
- secunia.com/advisories/31398nvdThird Party Advisory
- securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/30512nvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2008/2292nvdThird Party Advisory
- www.vupen.com/english/advisories/2008/2313nvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/44179nvdThird Party AdvisoryVDB Entry
- labs.idefense.com/intelligence/vulnerabilities/display.phpnvdBroken Link
- www.ingres.com/support/security-alert-080108.phpnvdBroken Link
- support.ca.com/irj/portal/anonymous/phpsupcontentnvdBroken Link
- www.securityfocus.com/archive/1/495177/100/0/threadednvd
News mentions
0No linked articles in our index yet.