4

CVE-2008-1966

Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 8.0
Ibm ≫ Db2 Version 8.0 Update fp1
Ibm ≫ Db2 Version 8.0 Update fp10
Ibm ≫ Db2 Version 8.0 Update fp11
Ibm ≫ Db2 Version 8.0 Update fp12
Ibm ≫ Db2 Version 8.0 Update fp13
Ibm ≫ Db2 Version 8.0 Update fp14
Ibm ≫ Db2 Version 8.0 Update fp15
Ibm ≫ Db2 Version 8.0 Update fp2
Ibm ≫ Db2 Version 8.0 Update fp3
Ibm ≫ Db2 Version 8.0 Update fp4
Ibm ≫ Db2 Version 8.0 Update fp4a
Ibm ≫ Db2 Version 8.0 Update fp5
Ibm ≫ Db2 Version 8.0 Update fp6
Ibm ≫ Db2 Version 8.0 Update fp6a
Ibm ≫ Db2 Version 8.0 Update fp6b
Ibm ≫ Db2 Version 8.0 Update fp6c
Ibm ≫ Db2 Version 8.0 Update fp7
Ibm ≫ Db2 Version 8.0 Update fp7a
Ibm ≫ Db2 Version 8.0 Update fp7b
Ibm ≫ Db2 Version 8.0 Update fp8
Ibm ≫ Db2 Version 8.0 Update fp8a
Ibm ≫ Db2 Version 8.0 Update fp9
Ibm ≫ Db2 Version 8.0 Update fp9a
Ibm ≫ Db2 Version 9.5
Ibm ≫ Db2 Version 9.1
Ibm ≫ Db2 Version 9.1 Update fp1
Ibm ≫ Db2 Version 9.1 Update fp2
Ibm ≫ Db2 Version 9.1 Update fp2a
Ibm ≫ Db2 Version 9.1 Update fp3
Ibm ≫ Db2 Version 9.1 Update fp3a
Ibm ≫ Db2 Version 9.1 Update fp4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.68% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www-1.ibm.com/support/docview.wss?uid=swg21255607
http://secunia.com/advisories/29022
Vendor Advisory
http://osvdb.org/46268
http://osvdb.org/46269
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ08512
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ08945
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ15496
http://www.appsecinc.com/resources/alerts/db2/2008-04.shtml
http://www.securityfocus.com/archive/1/491071/100/0/threaded
http://www.securityfocus.com/bid/28835
http://www.securityfocus.com/bid/29601
https://exchange.xforce.ibmcloud.com/vulnerabilities/41955