PT-2005-5530 · Ibm · Ibm Db2
Chris Anley
·
Published
2005-12-31
·
Updated
2017-07-29
·
CVE-2005-4869
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
IBM DB2 version 8.1
Description:
The issue concerns the
to char and to date functions, which allow local users to cause a denial of service, resulting in an application crash. This occurs when an empty string is passed as the second parameter, leading to a null pointer dereference.Recommendations:
For IBM DB2 version 8.1, consider restricting the use of the
to char and to date functions to prevent the denial of service, or apply any available configuration changes to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Db2