PT-2014-5085 · Ibm · Ibm Db2

Published

2014-09-04

·

Updated

2017-08-29

·

CVE-2014-3094

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM DB2 versions 9.7 through 9.7 FP9a IBM DB2 versions 9.8 through 9.8 FP5 IBM DB2 versions 10.1 through 10.1 FP4 IBM DB2 versions 10.5 before 10.5 FP4
Description A stack-based buffer overflow issue allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.
Recommendations For IBM DB2 versions 9.7 through 9.7 FP9a, update to a version after 9.7 FP9a. For IBM DB2 versions 9.8 through 9.8 FP5, update to a version after 9.8 FP5. For IBM DB2 versions 10.1 through 10.1 FP4, update to a version after 10.1 FP4. For IBM DB2 versions 10.5 before 10.5 FP4, update to 10.5 FP4 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3094

Affected Products

Ibm Db2