PT-2018-12383 · Ibm · Ibm Db2+2

Published

2018-03-22

·

Updated

2019-10-09

·

CVE-2018-1427

CVSS v3.1

6.2

Medium

VectorA:H/AC:L/AV:L/C:N/I:N/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions IBM GSKit (IBM DB2 for Linux, UNIX and Windows) versions 9.7 through 11.1
Description The issue concerns a local denial of service through environment variable overflows and a weakness in the GSKit CMS KDB logic. This logic fails to properly salt the hash function, resulting in weaker protection of passwords, which may allow a weak password to be recovered.
Recommendations For versions 9.7 through 11.1, update to a version that addresses these issues and change passwords to ensure they are stored more securely. As a temporary workaround, consider restricting access to sensitive areas until the update can be applied.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1427

Affected Products

Ibm Aix
Ibm Db2
Ibm Gskit