|
DB2 db2govd, db2start and db2stop Privilege Escalation Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA10173
|
|
|
Release Date:
|
2003-11-10
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
Privilege escalation
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | DB2 Universal Database 7.x DB2 Universal Database 8.x
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Some vulnerabilities have been reported in DB2, which can be exploited by malicious users to escalate their privileges.
The problem is that certain command line arguments aren't properly verified. This can be exploited by supplying overly long, specially crafted strings and string containing format specifiers, which may allow execution of arbitrary code with escalated privileges.
The vulnerabilities have been reported in versions 7.0 and 8.1.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution: IBM has issued FixPak 4 for DB2 version 8.1.
http://www-3.ibm.com/cgi-bin/db2www/d...inos2unix/support/download.d2w/report
IBM has scheduled a release of FixPak 11 for DB2 version 7.0 later in November.
Provided and/or discovered by: KF
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
21 Related Secunia Security Advisories, displaying 10
|
|
|
1. IBM DB2 Multiple Vulnerabilities
|
|
2. IBM DB2 UDB Multiple Vulnerabilities
|
|
3. IBM DB2 Multiple Vulnerabilities
|
|
4. IBM DB2 Universal Database Denial of Service and Buffer Overflows
|
|
5. IBM DB2 Fenced UserID Directory Access Authentication Bypass
|
|
6. IBM DB2 Authorisation Bypass Vulnerability
|
|
7. IBM DB2 Multiple Vulnerabilities
|
|
8. DB2 Universal Database Denial of Service Vulnerability
|
|
9. DB2 Universal Database Denial of Service Vulnerabilities
|
|
10. DB2 Universal Database Multiple Denial of Service Vulnerabilities
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|