PT-2007-5465 · Ibm · Ibm Db2 Udb
Publicado
2007-08-18
·
Atualizado
2017-07-29
·
CVE-2007-4273
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM DB2 UDB versions 8 before Fixpak 15
IBM DB2 UDB versions 9.1 before Fixpak 3
Description
The issue allows local users to create arbitrary directories and execute arbitrary code via a crafted localized message file, enabling a format string attack. This attack possibly involves the
OSSEMEMDBG or TRC LOG FILE environment variable in db2licd (db2licm).Recommendations
For IBM DB2 UDB versions 8 before Fixpak 15, apply Fixpak 15 to resolve the issue.
For IBM DB2 UDB versions 9.1 before Fixpak 3, apply Fixpak 3 to resolve the issue.
As a temporary workaround, consider restricting access to the
db2licd (db2licm) component until a patch is available.Correção
Use of Externally-Controlled Format String
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Db2 Udb