PT-2012-2806 · Ibm · Db2
Published
2012-03-20
·
Updated
2018-10-10
·
CVE-2012-0711
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.1 through 9.1 FP11
IBM DB2 versions 9.5 through 9.5 FP8
IBM DB2 versions 9.7 through 9.7 FP5
Description
The issue is related to an integer signedness error in the db2dasrrm process within the DB2 Administration Server (DAS) on UNIX platforms. This error can be exploited by remote attackers to execute arbitrary code through a crafted request, which triggers a heap-based buffer overflow.
Recommendations
For IBM DB2 version 9.1, update to a version later than 9.1 FP11.
For IBM DB2 version 9.5, update to a version later than 9.5 FP8.
For IBM DB2 version 9.7, update to a version later than 9.7 FP5.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Db2