IBM DB2 db2dart Buffer Overflow Vulnerability
BID:8552
Info
IBM DB2 db2dart Buffer Overflow Vulnerability
| Bugtraq ID: | 8552 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0758 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 18 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | Discovery of this vulnerability has been credited to Juan Pablo Martinez Kuhn from Core Security Technologies. |
| Vulnerable: |
IBM DB2 Universal Database for Linux 7.2 |
| Not Vulnerable: | |
Discussion
IBM DB2 db2dart Buffer Overflow Vulnerability
It has been reported that the IBM DB2 db2dart utility is prone to locally exploitable buffer overflow vulnerability. A local attacker, who can authenticate or has access as the db2as user, may exploit this issue to execute arbitrary instructions with elevated privileges. Specifically, user 'root' privileges.
Although this vulnerability has been reported to affect IBM DB2 v7.2 for Linux x86/s390 Other IBM DB2 versions and target platforms may also be affected.
It has been reported that the IBM DB2 db2dart utility is prone to locally exploitable buffer overflow vulnerability. A local attacker, who can authenticate or has access as the db2as user, may exploit this issue to execute arbitrary instructions with elevated privileges. Specifically, user 'root' privileges.
Although this vulnerability has been reported to affect IBM DB2 v7.2 for Linux x86/s390 Other IBM DB2 versions and target platforms may also be affected.