IBM DB2 CVE-2018-1566 Local Format String Vulnerability
BID:104740
CVE-2018-1566 |Info
IBM DB2 CVE-2018-1566 Local Format String Vulnerability
| Bugtraq ID: | 104740 |
| Class: | Design Error |
| CVE: |
CVE-2018-1566 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 11 2018 12:00AM |
| Updated: | Jul 11 2018 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM DB2 9.7 Fix Pack 6 0 IBM DB2 11.1.3 IBM DB2 11.1.2 FP2 IBM DB2 11.1.2 IBM DB2 10.1 .4 IBM DB2 9.7.0.9 A IBM DB2 9.7.0.9 IBM DB2 9.7.0.8 IBM DB2 9.7.0.7 IBM DB2 9.7.0.6 IBM DB2 9.7.0.5 IBM DB2 9.7.0.4 IBM DB2 9.7.0.3 IBM DB2 9.7.0.2 IBM DB2 9.7.0.1 IBM DB2 9.7 Fp5 IBM DB2 9.7 Fp3a IBM DB2 9.7 Fp2 IBM DB2 9.7 Fixpak 7 IBM DB2 9.7 Fixpak 6 IBM DB2 9.7 Fixpak 4 IBM DB2 9.7 Fixpack 4 IBM DB2 9.7 fixpack 3 IBM DB2 9.7 fixpack 2 IBM DB2 9.7 Fix Pack 7 IBM DB2 9.7 IBM DB2 11.1.3 FP3 IBM DB2 11.1.2.2 FP2 IBM DB2 11.1.0.0 IBM DB2 11.1 IBM DB2 10.5.0.7 IBM DB2 10.5.0.4 IBM DB2 10.5.0.3 A IBM DB2 10.5.0.3 IBM DB2 10.5.0.2 IBM DB2 10.5.0.1 IBM DB2 10.5 FP9 IBM DB2 10.5 FP8 IBM DB2 10.5 IBM DB2 10.1.0.3 A IBM DB2 10.1.0.3 IBM DB2 10.1.0.2 IBM DB2 10.1.0.1 IBM DB2 10.1 Fix Pack 1 IBM DB2 10.1 |
| Not Vulnerable: |
IBM DB2 9.7 FP11 IBM DB2 11.1.3.3 iFix001 IBM DB2 10.5 FP10 IBM DB2 10.1 FP6 |
Discussion
IBM DB2 CVE-2018-1566 Local Format String Vulnerability
IBM DB2 is prone to a local format-string vulnerability.
A local attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition. The attacker may also be able to execute arbitrary code within the context of the application, but this has not been confirmed.
IBM DB2 is prone to a local format-string vulnerability.
A local attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition. The attacker may also be able to execute arbitrary code within the context of the application, but this has not been confirmed.
Exploit / POC
IBM DB2 CVE-2018-1566 Local Format String Vulnerability
Attackers can use readily available command-line tools to exploit this issue.
Attackers can use readily available command-line tools to exploit this issue.
Solution / Fix
IBM DB2 CVE-2018-1566 Local Format String Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM DB2 CVE-2018-1566 Local Format String Vulnerability
References:
References: