PT-2005-5531 · Ibm · Db2
David Litchfield
·
Published
2005-12-31
·
Updated
2017-07-29
·
CVE-2005-4870
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM DB2 version 8.1
Description:
The issue is related to stack-based buffer overflows in specific function calls, allowing remote attackers to execute arbitrary code. The vulnerable function calls are xmlvarcharfromfile, xmlclobfromfile, xmlfilefromvarchar, and xmlfilefromclob. The overflow occurs when a 94-byte second argument is passed, causing the return address to be overwritten with a pointer to the argument.
Recommendations:
For IBM DB2 version 8.1, consider disabling the vulnerable function calls (xmlvarcharfromfile, xmlclobfromfile, xmlfilefromvarchar, and xmlfilefromclob) until a patch is available to prevent potential exploitation. Restrict access to these functions to minimize the risk of arbitrary code execution.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Db2