PT-2007-5465 · Ibm · Ibm Db2 Udb
Published
2007-08-18
·
Updated
2017-07-29
·
CVE-2007-4273
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM DB2 UDB versions 8 before Fixpak 15
IBM DB2 UDB versions 9.1 before Fixpak 3
Description
The issue allows local users to create arbitrary directories and execute arbitrary code via a crafted localized message file, enabling a format string attack. This attack possibly involves the
OSSEMEMDBG or TRC LOG FILE environment variable in db2licd (db2licm).Recommendations
For IBM DB2 UDB versions 8 before Fixpak 15, apply Fixpak 15 to resolve the issue.
For IBM DB2 UDB versions 9.1 before Fixpak 3, apply Fixpak 3 to resolve the issue.
As a temporary workaround, consider restricting access to the
db2licd (db2licm) component until a patch is available.Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Db2 Udb