PT-2018-12383 · Ibm · Ibm Db2+2
Published
2018-03-22
·
Updated
2019-10-09
·
CVE-2018-1427
CVSS v3.1
6.2
Medium
| Vector | A:H/AC:L/AV:L/C:N/I:N/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
IBM GSKit (IBM DB2 for Linux, UNIX and Windows) versions 9.7 through 11.1
Description
The issue concerns a local denial of service through environment variable overflows and a weakness in the GSKit CMS KDB logic. This logic fails to properly salt the hash function, resulting in weaker protection of passwords, which may allow a weak password to be recovered.
Recommendations
For versions 9.7 through 11.1, update to a version that addresses these issues and change passwords to ensure they are stored more securely. As a temporary workaround, consider restricting access to sensitive areas until the update can be applied.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Ibm Db2
Ibm Gskit