Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT | |
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ36534 | patch vendor advisory |
http://securitytracker.com/id?1021591 | vdb entry |
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT | |
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ37696 | vendor advisory |
http://secunia.com/advisories/33529 | third party advisory vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21363936 | patch vendor advisory |
http://www.vupen.com/english/advisories/2009/0137 | vdb entry |
http://www.securityfocus.com/bid/33258 | vdb entry patch |
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ37697 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/47931 | vdb entry |