10

CVE-2008-6821

Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 8.0 Update fp1
Ibm ≫ Db2 Version 8.0 Update fp10
Ibm ≫ Db2 Version 8.0 Update fp11
Ibm ≫ Db2 Version 8.0 Update fp12
Ibm ≫ Db2 Version 8.0 Update fp13
Ibm ≫ Db2 Version 8.0 Update fp14
Ibm ≫ Db2 Version 8.0 Update fp15
Ibm ≫ Db2 Version 8.0 Update fp16
Ibm ≫ Db2 Version 9.1 Update fp1
Ibm ≫ Db2 Version 9.1 Update fp2
Ibm ≫ Db2 Version 9.1 Update fp3
Ibm ≫ Db2 Version 9.1 Update fp3a
Ibm ≫ Db2 Version 9.1 Update fp4
Ibm ≫ Db2 Version 9.1 Update fp4a
Ibm ≫ Db2 Version 9.5 Update fp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.67% 0.882
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT
Patch
http://secunia.com/advisories/31787
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21318189
Patch
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ22004
Patch
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ22188
Patch
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ22190
Patch
Vendor Advisory
http://www.securityfocus.com/bid/35408
https://exchange.xforce.ibmcloud.com/vulnerabilities/51108