IBM DB2 Universal Database Security Service Remote Denial Of Service Vulnerability
BID:11405
Info
IBM DB2 Universal Database Security Service Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11405 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2004 12:00AM |
| Updated: | Sep 01 2004 12:00AM |
| Credit: | Discovery is credited to David Litchfield of NGSSoftware. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 Avaya Interactive Response 1.3 Avaya Interactive Response 1.2.1 Avaya Interactive Response Avaya CMS Server 13.0 Avaya CMS Server 12.0 Avaya CMS Server 11.0 Avaya CMS Server 9.0 Avaya CMS Server 8.0 |
| Not Vulnerable: | |
Discussion
IBM DB2 Universal Database Security Service Remote Denial Of Service Vulnerability
IBM DB2 universal Database Security Service is vulnerable to a remote denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed network messages.
An attacker may leverage this issue to cause the affected server to crash, denying service to legitimate users.
This is likely related to the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
IBM DB2 universal Database Security Service is vulnerable to a remote denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed network messages.
An attacker may leverage this issue to cause the affected server to crash, denying service to legitimate users.
This is likely related to the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
Exploit / POC
IBM DB2 Universal Database Security Service Remote Denial Of Service Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
IBM DB2 Universal Database Security Service Remote Denial Of Service Vulnerability
Solution:
The vendor has released FixPak 7a to address this issue.
Avaya has released advisory ASA-2005-114 and fixes to address this issue. Please see the referenced advisory for additional details.
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
Solution:
The vendor has released FixPak 7a to address this issue.
Avaya has released advisory ASA-2005-114 and fixes to address this issue. Please see the referenced advisory for additional details.
IBM DB2 Universal Database for Windows 8.0
IBM DB2 Universal Database for Windows 8.1
References
IBM DB2 Universal Database Security Service Remote Denial Of Service Vulnerability
References:
References:
- ASA-2005-114 (Avaya)
- DB2 V8 FixPaks 6 and 7 replaced with FixPaks 6a and 7a (IBM)
- IBM responds to DB2 UDB security vulnerability reports (IBM)
- IY62304:SECURITY:SENDING INVALID DATA TO DB2 SECURITY SERVICE COULD CAUSE CRASH (IBM)
- Patch available for critical IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
) - Patch available for IBM DB2 Universal Database flaws ("NGSSoftware Insight Security Research"
)