IBM DB2 DTS To String Conversion Denial Of Service Vulnerability
BID:11400
Info
IBM DB2 DTS To String Conversion Denial Of Service Vulnerability
| Bugtraq ID: | 11400 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Sep 01 2004 12:00AM |
| Credit: | Discovery is credited to Chris Anley of NGSSoftware. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 IBM DB2 Universal Database for Solaris 8.1 IBM DB2 Universal Database for Solaris 8.0 IBM DB2 Universal Database for Solaris 7.2 IBM DB2 Universal Database for Solaris 7.1 IBM DB2 Universal Database for Solaris 7.0 IBM DB2 Universal Database for Solaris 6.1 IBM DB2 Universal Database for Solaris 6.0 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 8.0 IBM DB2 Universal Database for Linux 7.2 IBM DB2 Universal Database for Linux 7.1 IBM DB2 Universal Database for Linux 7.0 IBM DB2 Universal Database for Linux 6.1 IBM DB2 Universal Database for Linux 6.0 IBM DB2 Universal Database for HP-UX 8.1 IBM DB2 Universal Database for HP-UX 8.0 IBM DB2 Universal Database for HP-UX 7.2 IBM DB2 Universal Database for HP-UX 7.1 IBM DB2 Universal Database for HP-UX 7.0 IBM DB2 Universal Database for HP-UX 6.1 IBM DB2 Universal Database for HP-UX 6.0 IBM DB2 Universal Database for AIX 8.1 IBM DB2 Universal Database for AIX 8.0 IBM DB2 Universal Database for AIX 7.2 IBM DB2 Universal Database for AIX 7.1 IBM DB2 Universal Database for AIX 7.0 IBM DB2 Universal Database for AIX 6.1 IBM DB2 Universal Database for AIX 6.0 |
| Not Vulnerable: | |
Discussion
IBM DB2 DTS To String Conversion Denial Of Service Vulnerability
IBM DB2 is reported prone to a denial of service vulnerability when DTS to string conversion is carried out.
It is reported that during a DTS to string conversion a trap occurs if an empty formatting string is provided. The vulnerability is exposed in the 'to_char' and 'to_date' conversion functions.
This is one of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
IBM DB2 is reported prone to a denial of service vulnerability when DTS to string conversion is carried out.
It is reported that during a DTS to string conversion a trap occurs if an empty formatting string is provided. The vulnerability is exposed in the 'to_char' and 'to_date' conversion functions.
This is one of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
Exploit / POC
IBM DB2 DTS To String Conversion Denial Of Service Vulnerability
There is no exploit required. The following examples were provided:
select to_char('aaa','') from sysibm.sysdummy1
select to_date('aaa', '') from sysibm.sysdummy1
There is no exploit required. The following examples were provided:
select to_char('aaa','') from sysibm.sysdummy1
select to_date('aaa', '') from sysibm.sysdummy1
Solution / Fix
IBM DB2 DTS To String Conversion Denial Of Service Vulnerability
Solution:
The vendor has released FixPak 6a and 7a to address this issues.
IBM DB2 Universal Database for AIX 8.0
IBM DB2 Universal Database for HP-UX 8.0
IBM DB2 Universal Database for Solaris 8.0
IBM DB2 Universal Database for Linux 8.0
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
IBM DB2 Universal Database for AIX 8.1
IBM DB2 Universal Database for Solaris 8.1
IBM DB2 Universal Database for Linux 8.1
IBM DB2 Universal Database for HP-UX 8.1
Solution:
The vendor has released FixPak 6a and 7a to address this issues.
IBM DB2 Universal Database for AIX 8.0
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for HP-UX 8.0
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Solaris 8.0
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Linux 8.0
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Windows 8.0
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Windows 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for AIX 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Solaris 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for Linux 8.1
-
IBM FixPak 6a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html -
IBM FixPak 7a
http://www-306.ibm.com/software/data/db2/udb/support/downloadv8.html
IBM DB2 Universal Database for HP-UX 8.1
References
IBM DB2 DTS To String Conversion Denial Of Service Vulnerability
References:
References:
- APARs included in DB2 UDB Version 8 FixPak 6a and FixPak 7a (IBM)
- DB2 V8 FixPaks 6 and 7 replaced with FixPaks 6a and 7a (IBM)
- IBM responds to DB2 UDB security vulnerability reports (IBM)
- IY61781: SECURITY: TRAP OCCURS WHEN PERFORMING DTS TO STRING CONVERSION (IBM)
- IBM DB2 to_char and to_date Denial Of Service (#NISR05012005G) ("NGSSoftware Insight Security Research"
) - Patch available for critical IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
) - Patch available for IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
)