PT-2004-1227 · Ibm · Ibm Db2 Universal Database

Publicado

2004-08-20

·

Atualizado

2017-07-11

·

CVE-2003-1051

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM DB2 Universal Database version 8.1
Description The issue concerns multiple format string vulnerabilities that may allow local users to execute arbitrary code. This can be achieved by providing certain command line arguments to specific commands, including (1) db2start, (2) db2stop, or (3) db2govd.
Recommendations For IBM DB2 Universal Database version 8.1, apply the necessary patches or updates to fix the format string vulnerabilities in the db2start, db2stop, and db2govd commands. As a temporary workaround, consider restricting access to these commands to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1051

Produtos afetados

Ibm Db2 Universal Database