CVE-2009-4325
Summary
| CVE | CVE-2009-4325 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-16 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 8.2 | All | All | All |
| Application | Ibm | Db2 | 8.2 | fp1 | All | All |
| Application | Ibm | Db2 | 8.2 | fp10 | All | All |
| Application | Ibm | Db2 | 8.2 | fp11 | All | All |
| Application | Ibm | Db2 | 8.2 | fp12 | All | All |
| Application | Ibm | Db2 | 8.2 | fp13 | All | All |
| Application | Ibm | Db2 | 8.2 | fp14 | All | All |
| Application | Ibm | Db2 | 8.2 | fp15 | All | All |
| Application | Ibm | Db2 | 8.2 | fp16 | All | All |
| Application | Ibm | Db2 | 8.2 | fp17 | All | All |
| Application | Ibm | Db2 | 8.2 | fp2 | All | All |
| Application | Ibm | Db2 | 8.2 | fp3 | All | All |
| Application | Ibm | Db2 | 8.2 | fp4 | All | All |
| Application | Ibm | Db2 | 8.2 | fp5 | All | All |
| Application | Ibm | Db2 | 8.2 | fp6 | All | All |
| Application | Ibm | Db2 | 8.2 | fp7 | All | All |
| Application | Ibm | Db2 | 8.2 | fp8 | All | All |
| Application | Ibm | Db2 | 8.2 | fp9 | All | All |
| Application | Ibm | Db2 | 9.1 | All | All | All |
| Application | Ibm | Db2 | 9.1 | fp1 | All | All |
| Application | Ibm | Db2 | 9.1 | fp2 | All | All |
| Application | Ibm | Db2 | 9.1 | fp3 | All | All |
| Application | Ibm | Db2 | 9.1 | fp3a | All | All |
| Application | Ibm | Db2 | 9.1 | fp4 | All | All |
| Application | Ibm | Db2 | 9.1 | fp4a | All | All |
| Application | Ibm | Db2 | 9.1 | fp5 | All | All |
| Application | Ibm | Db2 | 9.1 | fp6 | All | All |
| Application | Ibm | Db2 | 9.1 | fp6a | All | All |
| Application | Ibm | Db2 | 9.1 | fp7 | All | All |
| Application | Ibm | Db2 | 9.5 | All | All | All |
| Application | Ibm | Db2 | 9.5 | fp1 | All | All |
| Application | Ibm | Db2 | 9.5 | fp2 | All | All |
| Application | Ibm | Db2 | 9.5 | fp2a | All | All |
| Application | Ibm | Db2 | 9.5 | fp3 | All | All |
| Application | Ibm | Db2 | 9.5 | fp3a | All | All |
| Application | Ibm | Db2 | 9.5 | fp3b | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT | af854a3a-2127-422b-91ae-364da2661108 | ftp.software.ibm.com | |
| IC64702: ERROR HANDLING FOR EXTERNAL MEMORY OVERWRITE NULL POINTER | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM DB2 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT | af854a3a-2127-422b-91ae-364da2661108 | ftp.software.ibm.com | Patch |
| LI74504: ERROR HANDLING FOR EXTERNAL MEMORY OVERWRITE NULL POINTER | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT | af854a3a-2127-422b-91ae-364da2661108 | ftp.software.ibm.com | |
| IBM DB2 prior to 9.5 Fix Pack 5 Multiple Unspecified Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Fix List for DB2 Version 9.5 for Linux, UNIX and Windows - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| LI74500: ERROR HANDLING FOR EXTERNAL MEMORY OVERWRITE NULL POINTER | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Exploit, Vendor Advisory |
| ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT | af854a3a-2127-422b-91ae-364da2661108 | ftp.software.ibm.com | |
| LI72709: ERROR HANDLING FOR EXTERNAL MEMORY OVERWRITE NULL POINTER | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.