PT-2005-5530 · Ibm · Ibm Db2

Chris Anley

·

Published

2005-12-31

·

Updated

2017-07-29

·

CVE-2005-4869

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: IBM DB2 version 8.1
Description: The issue concerns the to char and to date functions, which allow local users to cause a denial of service, resulting in an application crash. This occurs when an empty string is passed as the second parameter, leading to a null pointer dereference.
Recommendations: For IBM DB2 version 8.1, consider restricting the use of the to char and to date functions to prevent the denial of service, or apply any available configuration changes to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4869

Affected Products

Ibm Db2