|
|
| |
| Buffer overflow on sysproc.auth_list_groups_for_authid function. By passing an overly long value of more then 40-bytes to the auth_list_groups_for_authid function, a stack-based buffer can be overflowed. |
| |
Credit:
The information has been provided by Team SHATTER.
The original article can be found at: http://www.appsecinc.com/resources/alerts/db2/2007-01.shtml
|
| |
Vulnerable Systems:
* DB2 version 9.1 Fixpack 2 Enterprise server edition
Immune Systems:
* DB2 version 9.1 Fixpack 3 Enterprise server edition
Impact:
An attacker can use this to cause a denial of service or take complete control of an affected system.
Vendor Status:
Vendor was contacted and a patch was released.
Fix:
To fix the problem apply the fixpak 3 for DB2 version 9.1 http://www-306.ibm.com/software/data/db2/support/db2_9/
|
|
|
|
|
|
|
|