PT-2007-5465 · Ibm · Ibm Db2 Udb

Published

2007-08-18

·

Updated

2017-07-29

·

CVE-2007-4273

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM DB2 UDB versions 8 before Fixpak 15 IBM DB2 UDB versions 9.1 before Fixpak 3
Description The issue allows local users to create arbitrary directories and execute arbitrary code via a crafted localized message file, enabling a format string attack. This attack possibly involves the OSSEMEMDBG or TRC LOG FILE environment variable in db2licd (db2licm).
Recommendations For IBM DB2 UDB versions 8 before Fixpak 15, apply Fixpak 15 to resolve the issue. For IBM DB2 UDB versions 9.1 before Fixpak 3, apply Fixpak 3 to resolve the issue. As a temporary workaround, consider restricting access to the db2licd (db2licm) component until a patch is available.

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4273

Affected Products

Ibm Db2 Udb