CVE-2008-3389 describes a stack-based buffer overflow in the libbecompat library affecting Ingres 2.6, Ingres 2006 release 1, and Ingres 2006 release 2 on Linux and HP-UX systems. This vulnerability allows a local attacker to gain elevated privileges by manipulating environment variables before executing specific Ingres utilities. With a CVSS score of 4.6, it is considered a medium-severity vulnerability, requiring local access and user interaction to achieve partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6CPE matchmatch criteria | cpe:2.3:a:ingres:ingres:2.6:*:*:*:*:*:*:* | ||
2006CPE matchmatch criteria | cpe:2.3:a:ingres:ingres:2006:9.0.4:*:*:*:*:*:* | ||
2006CPE matchmatch criteria | cpe:2.3:a:ingres:ingres:2006:9.1.0:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.