CVE-2014-3094
Summary
| CVE | CVE-2014-3094 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-04 10:55:00 UTC |
| Updated | 2017-08-29 01:34:00 UTC |
| Description | Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.4 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | a | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.5 | All | All | All |
| Application | Ibm | Db2 | 10.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.1.0.4 | All | All | All |
| Application | Ibm | Db2 | 10.5 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.1 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.2 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | All | All | All |
| Application | Ibm | Db2 | 10.5.0.3 | a | All | All |
| Application | Ibm | Db2 | 9.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.1 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.2 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.5 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.6 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.7 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.8 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | All | All | All |
| Application | Ibm | Db2 | 9.7.0.9 | a | All | All |
| Application | Ibm | Db2 | 9.8 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.3 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.4 | All | All | All |
| Application | Ibm | Db2 | 9.8.0.5 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM IT02593: Security: DB2 contains a denial of service vulnerability in ALTER MODULE statement handling. (CVE-2014-3094) - United States | AIXAPAR | www-01.ibm.com | Vendor Advisory |
| IBM IT02291: Security: DB2 contains a denial of service vulnerability in ALTER MODULE statement handling. (CVE-2014-3094) - United States | AIXAPAR | www-01.ibm.com | Vendor Advisory |
| Security Bulletin: IBM® DB2® LUW contains a denial of service vulnerability in ALTER MODULE statement handling. (CVE-2014-3094) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| Multiple IBM DB2 Products CVE-2014-3094 Stack Based Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| IBM IT02592: Security: DB2 contains a denial of service vulnerability in ALTER MODULE statement handling. (CVE-2014-3094) - United States | AIXAPAR | www-01.ibm.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IT02594 | AIXAPAR | www-01.ibm.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| Security Advisory SA60845 - IBM DB2 / DB2 Connect Multiple Vulnerabilities - Secunia | SECUNIA | secunia.com | |
| Security Bulletin: IBM® InfoSphere Balanced Warehouse, IBM Smart Analytics System and IBM PureData System for Operational Analytics are affected by an IBM DB2® LUW denial of service vulnerability in ALTER MODULE statement handling (CVE-2014-3094) | CONFIRM | www-01.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.