IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
BID:25339
Info
IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
| Bugtraq ID: | 25339 |
| Class: | Unknown |
| CVE: |
CVE-2007-4270 CVE-2007-4271 CVE-2007-4272 CVE-2007-4273 CVE-2007-4275 CVE-2007-4276 CVE-2007-4417 CVE-2007-4418 CVE-2007-4423 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 16 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | The vendor reported some of these issues. Joshua J. Drake (iDefense Labs) and anonymous researchers also found some of these issues. Ariel Sanchez of Application Security, Inc. discovered the AUTH_LIST_GROUPS_FOR_AUTHID issue. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.12 IBM DB2 Universal Database for Windows 8.10 IBM DB2 Universal Database for Windows 8.2 IBM DB2 Universal Database for Windows 8.1.9 a IBM DB2 Universal Database for Windows 8.1.9 IBM DB2 Universal Database for Windows 8.1.8 a IBM DB2 Universal Database for Windows 8.1.8 IBM DB2 Universal Database for Windows 8.1.7 b IBM DB2 Universal Database for Windows 8.1.7 IBM DB2 Universal Database for Windows 8.1.6 c IBM DB2 Universal Database for Windows 8.1.6 IBM DB2 Universal Database for Windows 8.1.5 IBM DB2 Universal Database for Windows 8.1.4 IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 9.1 FixPack 2 IBM DB2 Universal Database for Windows 9.1 IBM DB2 Universal Database for Windows 9.0 Fix Pack 2 IBM DB2 Universal Database for Windows 8.2 FixPak 7 IBM DB2 Universal Database for Windows 8.1 FixPak 14 IBM DB2 Universal Database for Windows 8.0 FixPak 13 IBM DB2 Universal Database for Solaris 9.0 IBM DB2 Universal Database for Solaris 8.12 IBM DB2 Universal Database for Solaris 8.10 IBM DB2 Universal Database for Solaris 8.2 IBM DB2 Universal Database for Solaris 8.1.9 a IBM DB2 Universal Database for Solaris 8.1.9 IBM DB2 Universal Database for Solaris 8.1.8 a IBM DB2 Universal Database for Solaris 8.1.8 IBM DB2 Universal Database for Solaris 8.1.7 b IBM DB2 Universal Database for Solaris 8.1.7 IBM DB2 Universal Database for Solaris 8.1.6 c IBM DB2 Universal Database for Solaris 8.1.6 IBM DB2 Universal Database for Solaris 8.1.5 IBM DB2 Universal Database for Solaris 8.1.4 IBM DB2 Universal Database for Solaris 8.1 IBM DB2 Universal Database for Solaris 8.0 IBM DB2 Universal Database for Solaris 9.1 FixPack 2 IBM DB2 Universal Database for Solaris 9.1 IBM DB2 Universal Database for Solaris 9.0.0 Fixpak 1 IBM DB2 Universal Database for Solaris 9.0 Fix Pack 2 IBM DB2 Universal Database for Solaris 8.2 FixPak 7 IBM DB2 Universal Database for Solaris 8.1 FixPak 14 IBM DB2 Universal Database for Solaris 8.0 FixPak 13 IBM DB2 Universal Database for Linux 9.0 IBM DB2 Universal Database for Linux 8.12 IBM DB2 Universal Database for Linux 8.10 IBM DB2 Universal Database for Linux 8.2 IBM DB2 Universal Database for Linux 8.1.9 a IBM DB2 Universal Database for Linux 8.1.9 IBM DB2 Universal Database for Linux 8.1.8 a IBM DB2 Universal Database for Linux 8.1.8 IBM DB2 Universal Database for Linux 8.1.7 b IBM DB2 Universal Database for Linux 8.1.7 IBM DB2 Universal Database for Linux 8.1.6 c IBM DB2 Universal Database for Linux 8.1.6 IBM DB2 Universal Database for Linux 8.1.5 IBM DB2 Universal Database for Linux 8.1.4 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 8.0 IBM DB2 Universal Database for Linux 9.1 FixPack 2 IBM DB2 Universal Database for Linux 9.1 IBM DB2 Universal Database for Linux 9.0.0 Fixpack 1 IBM DB2 Universal Database for Linux 9.0 Fix Pack 2 IBM DB2 Universal Database for Linux 8.2 FixPak 7 IBM DB2 Universal Database for Linux 8.1 FixPak 14 IBM DB2 Universal Database for Linux 8.0 FixPak 13 IBM DB2 Universal Database for HP-UX 9.0 IBM DB2 Universal Database for HP-UX 8.12 IBM DB2 Universal Database for HP-UX 8.10 IBM DB2 Universal Database for HP-UX 8.2 IBM DB2 Universal Database for HP-UX 8.1.9 a IBM DB2 Universal Database for HP-UX 8.1.9 IBM DB2 Universal Database for HP-UX 8.1.8 a IBM DB2 Universal Database for HP-UX 8.1.8 IBM DB2 Universal Database for HP-UX 8.1.7 b IBM DB2 Universal Database for HP-UX 8.1.7 IBM DB2 Universal Database for HP-UX 8.1.6 c IBM DB2 Universal Database for HP-UX 8.1.6 IBM DB2 Universal Database for HP-UX 8.1.5 IBM DB2 Universal Database for HP-UX 8.1.4 IBM DB2 Universal Database for HP-UX 8.1 IBM DB2 Universal Database for HP-UX 8.0 IBM DB2 Universal Database for HP-UX 9.1 FixPack 2 IBM DB2 Universal Database for HP-UX 9.1 IBM DB2 Universal Database for HP-UX 9.0.0 Fixpak 1 IBM DB2 Universal Database for HP-UX 9.0 Fix Pack 2 IBM DB2 Universal Database for HP-UX 8.2 FixPak 7 IBM DB2 Universal Database for HP-UX 8.1 FixPak 14 IBM DB2 Universal Database for HP-UX 8.0 FixPak 13 IBM DB2 Universal Database for AIX 9.0 IBM DB2 Universal Database for AIX 8.12 IBM DB2 Universal Database for AIX 8.10 IBM DB2 Universal Database for AIX 8.2 IBM DB2 Universal Database for AIX 8.1.9 a IBM DB2 Universal Database for AIX 8.1.9 IBM DB2 Universal Database for AIX 8.1.8 a IBM DB2 Universal Database for AIX 8.1.8 IBM DB2 Universal Database for AIX 8.1.7 b IBM DB2 Universal Database for AIX 8.1.7 IBM DB2 Universal Database for AIX 8.1.6 c IBM DB2 Universal Database for AIX 8.1.6 IBM DB2 Universal Database for AIX 8.1.5 IBM DB2 Universal Database for AIX 8.1.4 IBM DB2 Universal Database for AIX 8.1 IBM DB2 Universal Database for AIX 8.0 IBM DB2 Universal Database for AIX 9.1 FixPack 2 IBM DB2 Universal Database for AIX 9.1 IBM DB2 Universal Database for AIX 9.0.0 Fixpak 1 IBM DB2 Universal Database for AIX 9.0 Fix Pack 2 IBM DB2 Universal Database for AIX 8.2 FixPak 7 IBM DB2 Universal Database for AIX 8.1 FixPak 14 IBM DB2 Universal Database for AIX 8.0 FixPak 13 |
| Not Vulnerable: |
IBM DB2 Universal Database for Windows 9.1 FixPak 3 IBM DB2 Universal Database for Windows 8.1 FixPak 15 IBM DB2 Universal Database for Solaris 9.1 FixPak 3 IBM DB2 Universal Database for Solaris 8.1 FixPak 15 IBM DB2 Universal Database for Linux 9.1 FixPak 3 IBM DB2 Universal Database for Linux 8.1 FixPak 15 IBM DB2 Universal Database for HP-UX 9.1 FixPak 3 IBM DB2 Universal Database for HP-UX 8.1 FixPak 15 IBM DB2 Universal Database for AIX 9.1 FixPak 3 IBM DB2 Universal Database for AIX 8.1 FixPak 15 |
Discussion
IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
IBM DB2 is prone to multiple vulnerabilities that may allow an attacker to carry out various attacks.
Some of these issues may permit the attacker to completely compromise a vulnerable computer.
These issues affect DB2 9.1 and 8 running on all supported platforms.
IBM DB2 is prone to multiple vulnerabilities that may allow an attacker to carry out various attacks.
Some of these issues may permit the attacker to completely compromise a vulnerable computer.
These issues affect DB2 9.1 and 8 running on all supported platforms.
Exploit / POC
IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
Some of these issues may not require exploit code and may be triggered using existing operating system utilities.
Currently we are not aware of any exploits for the memory-corruption issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require exploit code and may be triggered using existing operating system utilities.
Currently we are not aware of any exploits for the memory-corruption issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
Solution:
IBM has released DB2 9.1 Fixpak 3 and 8.1 Fixpak 15 to address these issues. Please see the references for more information.
Solution:
IBM has released DB2 9.1 Fixpak 3 and 8.1 Fixpak 15 to address these issues. Please see the references for more information.
References
IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
References:
References:
- DB2 Technical Support (IBM)
- DB2 UDB Version 8 APARs by FixPak (IBM)
- DB2 UDB Version 8 FixPaks and clients (IBM)
- DB2 Version 9.1 fix packs and clients (IBM)
- DB2 Version 9.1 for Linux, UNIX and Windows APARs by fix pack (IBM)
- IY88226: SECURITY: EXECUTE AUTHORITY ON A METHOD MAY PERSIST AFTER REVOKE. (IBM)
- iDefense Security Advisory 08.16.07: IBM DB2 Universal Database buildDasPaths Bu (iDefense Labs
) - iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Directory Creati (iDefense Labs
) - iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Directory Traver (iDefense Labs
) - iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Multiple File Cr (iDefense Labs
) - iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Multiple Race Co (iDefense Labs
) - iDefense Security Advisory 08.16.07: IBM DB2 Universal Database Multiple Untrust (iDefense Labs
) - Team SHATTER Advisory: IBM DB2 Buffer overflow in sysproc.auth_list_groups_for_a (Team SHATTER
) - IBM DB2 Buffer overflow in sysproc.auth_list_groups_for_authid (Application Security, Inc.)
- IZ01828: SECURITY VULNERABILITY IN AUTH_LIST_GROUPS_FOR_AUTHID. (IBM)