If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
Go Back  dBforums > Database Server Software > DB2 > Multiple Remote Buffer Overflow And Unspecified Vulnerabilities

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-07-04, 15:16
udbraja udbraja is offline
Registered User
 
Join Date: Sep 2004
Posts: 111
Angry Multiple Remote Buffer Overflow And Unspecified Vulnerabilities

Team,

Any body come across this problem.

SUBJECT:IBM DB2 Universal Database Multiple Remote Buffer Overflow And Unspecified Vulnerabilities

CONTENT:
The remote buffer overflow vulnerabilities exist, ultimately resulting in execution of arbitrary code. Details NGSSoftware have reported that multiple remote buffer overflow and other unspecified vulnerabilities exist in IBM DB2 Universal Database.

The reported vulnerabilities include two remote buffer overflows that are reported to be of 'critical' severity.* Details about any of the vulnerabilities are not known at this time.
Affected Technology and Version:
IBM DB2 Universal Database for AIX: 7.0.0-, 7.1.0-, 7.2.0-, 8.1.0
IBM DB2 Universal Database for HP-UX: 7.0.0-, 7.1.0-, 7.2.0-, 8.1.0
IBM DB2 Universal Database for Linux: 7.0.0-, 7.1.0-, 7.2.0-, 8.1.0
IBM DB2 Universal Database for Solaris: 7.0.0-, 7.1.0-, 7.2.0-, 8.1.0 I
BM DB2 Universal Database for Windows: 7.1.0-, 7.2.0-, 8.1.0

Thank you in advance for your REPILES.

-Raj
Reply With Quote
  #2 (permalink)  
Old 09-10-04, 09:08
Romeo Romeo is offline
Registered User
 
Join Date: Feb 2002
Location: Philippines
Posts: 41
The remotely exploitable buffer overflows and other issues have been fixed in Fixpak 7 for DB2 8.1 and Fixpak 12 for DB2 7.x. These Fixpaks were released last week and they can be downloaded from

http://www-306.ibm.com/software/data...ownloadv8.html - DB2 v8.1
http://www-306.ibm.com/software/data...ownloadv7.html - DB2 v7.x
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On