PT-2014-5085 · Ibm · Ibm Db2
Published
2014-09-04
·
Updated
2017-08-29
·
CVE-2014-3094
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM DB2 versions 9.7 through 9.7 FP9a
IBM DB2 versions 9.8 through 9.8 FP5
IBM DB2 versions 10.1 through 10.1 FP4
IBM DB2 versions 10.5 before 10.5 FP4
Description
A stack-based buffer overflow issue allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.
Recommendations
For IBM DB2 versions 9.7 through 9.7 FP9a, update to a version after 9.7 FP9a.
For IBM DB2 versions 9.8 through 9.8 FP5, update to a version after 9.8 FP5.
For IBM DB2 versions 10.1 through 10.1 FP4, update to a version after 10.1 FP4.
For IBM DB2 versions 10.5 before 10.5 FP4, update to 10.5 FP4 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Db2