IBM DB2 XML Extender UDF Buffer Overflow Vulnerabilities
BID:11404
Info
IBM DB2 XML Extender UDF Buffer Overflow Vulnerabilities
| Bugtraq ID: | 11404 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Sep 01 2004 12:00AM |
| Credit: | Discovery is credited to David Litchfield of NGSSoftware. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 IBM DB2 Universal Database for Solaris 8.1 IBM DB2 Universal Database for Solaris 8.0 IBM DB2 Universal Database for Solaris 7.2 IBM DB2 Universal Database for Solaris 7.1 IBM DB2 Universal Database for Solaris 7.0 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 8.0 IBM DB2 Universal Database for Linux 7.2 IBM DB2 Universal Database for Linux 7.1 IBM DB2 Universal Database for Linux 7.0 IBM DB2 Universal Database for HP-UX 8.1 IBM DB2 Universal Database for HP-UX 8.0 IBM DB2 Universal Database for HP-UX 7.2 IBM DB2 Universal Database for HP-UX 7.1 IBM DB2 Universal Database for HP-UX 7.0 IBM DB2 Universal Database for AIX 8.1 IBM DB2 Universal Database for AIX 8.0 IBM DB2 Universal Database for AIX 7.2 IBM DB2 Universal Database for AIX 7.1 IBM DB2 Universal Database for AIX 7.0 |
| Not Vulnerable: | |
Discussion
IBM DB2 XML Extender UDF Buffer Overflow Vulnerabilities
Remotely exploitable buffer overflow vulnerabilities exist in IBM DB2. These issues are due to insufficient bounds checking of data handled through XML Extender UDF's.
Successful exploitation may allow execution of arbitrary code with the privilege of the DB2 UDB processes. It is reported that privileged code execution is also possible.
These are likely some of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
Remotely exploitable buffer overflow vulnerabilities exist in IBM DB2. These issues are due to insufficient bounds checking of data handled through XML Extender UDF's.
Successful exploitation may allow execution of arbitrary code with the privilege of the DB2 UDB processes. It is reported that privileged code execution is also possible.
These are likely some of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
Exploit / POC
IBM DB2 XML Extender UDF Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM DB2 XML Extender UDF Buffer Overflow Vulnerabilities
Solution:
The vendor has released FixPak 6a and 7a to address these issues.
IBM DB2 Universal Database for AIX 8.0
IBM DB2 Universal Database for HP-UX 8.0
IBM DB2 Universal Database for Solaris 8.0
IBM DB2 Universal Database for Linux 8.0
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
IBM DB2 Universal Database for AIX 8.1
IBM DB2 Universal Database for Solaris 8.1
IBM DB2 Universal Database for Linux 8.1
IBM DB2 Universal Database for HP-UX 8.1
Solution:
The vendor has released FixPak 6a and 7a to address these issues.
IBM DB2 Universal Database for AIX 8.0
IBM DB2 Universal Database for HP-UX 8.0
IBM DB2 Universal Database for Solaris 8.0
IBM DB2 Universal Database for Linux 8.0
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
IBM DB2 Universal Database for AIX 8.1
IBM DB2 Universal Database for Solaris 8.1
IBM DB2 Universal Database for Linux 8.1
IBM DB2 Universal Database for HP-UX 8.1
References
IBM DB2 XML Extender UDF Buffer Overflow Vulnerabilities
References:
References:
- APARs included in DB2 UDB Version 8 FixPak 6a and FixPak 7a (IBM)
- DB2 V8 FixPaks 6 and 7 replaced with FixPaks 6a and 7a (IBM)
- IBM responds to DB2 UDB security vulnerability reports (IBM)
- IY62297: SECURITY: PASSING A VERY LONG PARAMETER VALUE TO SOME XML EXTENDER UDFS (IBM)
- IBM DB2 XML functions overflows (#NISR05012005H) ("NGSSoftware Insight Security Research"
) - Patch available for critical IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
) - Patch available for IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
)