CVE-2008-3854

Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2_universal_database:9.1:*:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:hp_ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:*:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp2:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp3:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.1:fp4a:windows:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.5:*:aix:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.5:*:hp-ux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.5:*:linux:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.5:*:solaris:*:*:*:*:*
cpe:2.3:a:ibm:db2_universal_database:9.5:*:windows:*:*:*:*:*

History

21 Nov 2024, 00:50

Type Values Removed Values Added
References () http://secunia.com/advisories/30558 - Patch, Vendor Advisory () http://secunia.com/advisories/30558 - Patch, Vendor Advisory
References () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ16346 - Patch () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ16346 - Patch
References () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ18431 - () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ18431 -
References () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ18434 - Patch () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ18434 - Patch
References () http://www-1.ibm.com/support/docview.wss?uid=swg21255607 - Patch () http://www-1.ibm.com/support/docview.wss?uid=swg21255607 - Patch
References () http://www.securityfocus.com/archive/1/496406/100/0/threaded - () http://www.securityfocus.com/archive/1/496406/100/0/threaded -
References () http://www.securityfocus.com/bid/29601 - Patch () http://www.securityfocus.com/bid/29601 - Patch
References () http://www.vupen.com/english/advisories/2008/1769 - Vendor Advisory () http://www.vupen.com/english/advisories/2008/1769 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/42930 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/42930 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/42935 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/42935 -

Information

Published : 2008-08-28 17:41

Updated : 2024-11-21 00:50


NVD link : CVE-2008-3854

Mitre link : CVE-2008-3854

CVE.ORG link : CVE-2008-3854


JSON object : View

Products Affected

ibm

  • db2_universal_database
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer