5

CVE-2009-4327

The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Version 9.5
Ibm ≫ Db2 Version 9.5 Update fp1
Ibm ≫ Db2 Version 9.5 Update fp2
Ibm ≫ Db2 Version 9.5 Update fp2a
Ibm ≫ Db2 Version 9.5 Update fp3
Ibm ≫ Db2 Version 9.5 Update fp3a
Ibm ≫ Db2 Version 9.5 Update fp3b
Ibm ≫ Db2 Version 9.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.35% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT
http://www-01.ibm.com/support/docview.wss?uid=swg21293566
Patch
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT
http://secunia.com/advisories/37759
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21412902
Vendor Advisory
http://www.securityfocus.com/bid/37332
http://www.vupen.com/english/advisories/2009/3520
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IC63179
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ43772