IBM DB2 Remote LOAD Command Buffer Overrun Vulnerability
BID:8742
Info
IBM DB2 Remote LOAD Command Buffer Overrun Vulnerability
| Bugtraq ID: | 8742 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0836 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | The discovery of this vulnerability has been credited to Mark Rowe. |
| Vulnerable: |
IBM DB2 Universal Database for Windows 8.1 IBM DB2 Universal Database for Windows 8.0 IBM DB2 Universal Database for Windows 7.2 IBM DB2 Universal Database for Windows 7.1 IBM DB2 Universal Database for Linux 8.1 IBM DB2 Universal Database for Linux 8.0 IBM DB2 Universal Database for Linux 7.2 IBM DB2 Universal Database for Linux 7.1 IBM DB2 Universal Database for Linux 7.0 |
| Not Vulnerable: | |
Discussion
IBM DB2 Remote LOAD Command Buffer Overrun Vulnerability
A vulnerability has been discovered in IBM DB2. The problem occurs due to insufficient bounds checking when handling the LOAD command. As a result, a remote attacker with sufficient privileges may be capable of trigger a buffer overrun. This would effectively allow for the execution flow of IBM DB2 to be controlled, and could ultimately result in the execution of attacker-supplied code with the privileges of the target process.
A vulnerability has been discovered in IBM DB2. The problem occurs due to insufficient bounds checking when handling the LOAD command. As a result, a remote attacker with sufficient privileges may be capable of trigger a buffer overrun. This would effectively allow for the execution flow of IBM DB2 to be controlled, and could ultimately result in the execution of attacker-supplied code with the privileges of the target process.
Exploit / POC
IBM DB2 Remote LOAD Command Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM DB2 Remote LOAD Command Buffer Overrun Vulnerability
Solution:
IBM has released a Fixpack to address this issue.
IBM DB2 Universal Database for Windows 7.2
IBM DB2 Universal Database for Linux 7.2
IBM DB2 Universal Database for Windows 8.1
IBM DB2 Universal Database for Linux 8.1
Solution:
IBM has released a Fixpack to address this issue.
IBM DB2 Universal Database for Windows 7.2
-
IBM Fixpak 10/10a
http://www-3.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/do wnload.d2w/report
IBM DB2 Universal Database for Linux 7.2
-
IBM Fixpak 10/10a
http://www-3.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/do wnload.d2w/report
IBM DB2 Universal Database for Windows 8.1
-
IBM Fixpak 2
http://www-3.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/do wnload.d2w/report
IBM DB2 Universal Database for Linux 8.1
References
IBM DB2 Remote LOAD Command Buffer Overrun Vulnerability
References:
References:
- DB2 Technical Support (IBM)
- DB2 Universal Database Product Page (IBM)
- ptl-2003-01: IBM DB2 LOAD Command Stack Overflow Vulnerability (Pentest Security Advisories
)