PT-2012-2806 · Ibm · Db2
Publicado
2012-03-20
·
Atualizado
2018-10-10
·
CVE-2012-0711
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.1 through 9.1 FP11
IBM DB2 versions 9.5 through 9.5 FP8
IBM DB2 versions 9.7 through 9.7 FP5
Description
The issue is related to an integer signedness error in the db2dasrrm process within the DB2 Administration Server (DAS) on UNIX platforms. This error can be exploited by remote attackers to execute arbitrary code through a crafted request, which triggers a heap-based buffer overflow.
Recommendations
For IBM DB2 version 9.1, update to a version later than 9.1 FP11.
For IBM DB2 version 9.5, update to a version later than 9.5 FP8.
For IBM DB2 version 9.7, update to a version later than 9.7 FP5.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Db2