IBM DB2 DB2FMP Command String Buffer Overflow Vulnerability
BID:11397
Info
IBM DB2 DB2FMP Command String Buffer Overflow Vulnerability
| Bugtraq ID: | 11397 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Sep 01 2004 12:00AM |
| Credit: | Discovery is credited to David Litchfield of NGSSoftware. |
| Vulnerable: |
IBM DB2 Universal Database for Solaris 8.1 IBM DB2 Universal Database for Solaris 7.2 IBM DB2 Universal Database for Solaris 7.1 IBM DB2 Universal Database for Solaris 7.0 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 7.2 IBM DB2 Universal Database for Linux 7.1 IBM DB2 Universal Database for Linux 7.0 IBM DB2 Universal Database for HP-UX 8.1 IBM DB2 Universal Database for HP-UX 7.2 IBM DB2 Universal Database for HP-UX 7.1 IBM DB2 Universal Database for HP-UX 7.0 IBM DB2 Universal Database for AIX 8.1 IBM DB2 Universal Database for AIX 7.2 IBM DB2 Universal Database for AIX 7.1 IBM DB2 Universal Database for AIX 7.0 |
| Not Vulnerable: | |
Discussion
IBM DB2 DB2FMP Command String Buffer Overflow Vulnerability
A locally exploitable buffer overflow exists in IBM DB2. This issue is due to insufficient bounds checking of data passed in a command string to the DB2FMP executable.
Successful exploitation may allow execution of arbitrary code with elevated privileges.
This is likely one of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
It is reported that some versions of DB2FMP may drop superuser privileges prior to the overflow condition being exploitable.
A locally exploitable buffer overflow exists in IBM DB2. This issue is due to insufficient bounds checking of data passed in a command string to the DB2FMP executable.
Successful exploitation may allow execution of arbitrary code with elevated privileges.
This is likely one of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
It is reported that some versions of DB2FMP may drop superuser privileges prior to the overflow condition being exploitable.
Exploit / POC
IBM DB2 DB2FMP Command String Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM DB2 DB2FMP Command String Buffer Overflow Vulnerability
Solution:
The vendor has released FixPak 6a and 7a to address this issue.
IBM DB2 Universal Database for AIX 8.1
IBM DB2 Universal Database for Solaris 8.1
IBM DB2 Universal Database for Linux 8.1
IBM DB2 Universal Database for HP-UX 8.1
Solution:
The vendor has released FixPak 6a and 7a to address this issue.
IBM DB2 Universal Database for AIX 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Solaris 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Linux 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for HP-UX 8.1
References
IBM DB2 DB2FMP Command String Buffer Overflow Vulnerability
References:
References:
- APARs included in DB2 UDB Version 8 FixPak 6a and FixPak 7a (IBM)
- DB2 V8 FixPaks 6 and 7 replaced with FixPaks 6a and 7a (IBM)
- IBM responds to DB2 UDB security vulnerability reports (IBM)
- IBM DB2 db2fmp buffer overflow (#NISR05012005A) ("NGSSoftware Insight Security Research"
) - Patch available for critical IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
) - Patch available for IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
)