PT-2005-5531 · Ibm · Db2
David Litchfield
·
Publicado
2005-12-31
·
Atualizado
2017-07-29
·
CVE-2005-4870
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM DB2 version 8.1
Description:
The issue is related to stack-based buffer overflows in specific function calls, allowing remote attackers to execute arbitrary code. The vulnerable function calls are xmlvarcharfromfile, xmlclobfromfile, xmlfilefromvarchar, and xmlfilefromclob. The overflow occurs when a 94-byte second argument is passed, causing the return address to be overwritten with a pointer to the argument.
Recommendations:
For IBM DB2 version 8.1, consider disabling the vulnerable function calls (xmlvarcharfromfile, xmlclobfromfile, xmlfilefromvarchar, and xmlfilefromclob) until a patch is available to prevent potential exploitation. Restrict access to these functions to minimize the risk of arbitrary code execution.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Db2