PT-2010-2840 · Ibm · Db2+2

Publicado

2010-03-26

·

Atualizado

2010-03-29

·

CVE-2010-1124

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions bos.rte.libc version 5.3.9.4 on IBM AIX 5.3
Description The issue is related to the improper support of reading a certain address field after a successful getaddrinfo function call. This can be exploited by context-dependent attackers to cause a denial of service, resulting in an application crash. The problem has been demonstrated by crashes in IBM DB2 on systems with databases cataloged with alternate servers using IP addresses.
Recommendations For bos.rte.libc version 5.3.9.4 on IBM AIX 5.3, consider applying configuration changes to handle address fields properly after getaddrinfo function calls to prevent application crashes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-1124

Produtos afetados

Aix
Db2
Bos.Rte.Libc