IBM DB2 Denial of Service Vulnerability
BID:3010
Info
IBM DB2 Denial of Service Vulnerability
| Bugtraq ID: | 3010 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1143 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was submitted to BugTraq on July 11th, 2001 by "LAMI, Gilles - DSIA" <[email protected]>. |
| Vulnerable: |
IBM DB2 Universal Database Win98/NT/2000 7.0 |
| Not Vulnerable: | |
Discussion
IBM DB2 Denial of Service Vulnerability
IBM DB2 is a commercial database suite which is available for a variety of platforms.
Remote attackers can crash remote services by sending only one byte of data to them. These services listen on ports 6789 and 6790. Affected services must be rebooted to regain normal functionality.
IBM DB2 is a commercial database suite which is available for a variety of platforms.
Remote attackers can crash remote services by sending only one byte of data to them. These services listen on ports 6789 and 6790. Affected services must be rebooted to regain normal functionality.
Exploit / POC
IBM DB2 Denial of Service Vulnerability
No exploit is required, attacker only has to telnet to the affected services.
No exploit is required, attacker only has to telnet to the affected services.
Solution / Fix
IBM DB2 Denial of Service Vulnerability
Solution:
Vendor has been notified and a patch is pending.
Solution:
Vendor has been notified and a patch is pending.