CVE-2009-1906

The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp2:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp3:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp3a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp4:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp4a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp5:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp6:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.1:fp6a:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp2:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.5:fp3:*:*:*:*:*:*

History

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://secunia.com/advisories/35235 - Vendor Advisory () http://secunia.com/advisories/35235 - Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ36683 - Exploit, Patch, Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ36683 - Exploit, Patch, Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ38874 - Exploit, Patch, Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ38874 - Exploit, Patch, Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?uid=swg21293566 - Patch () http://www-01.ibm.com/support/docview.wss?uid=swg21293566 - Patch
References () http://www.securityfocus.com/bid/35171 - () http://www.securityfocus.com/bid/35171 -

Information

Published : 2009-06-03 21:00

Updated : 2024-11-21 01:03


NVD link : CVE-2009-1906

Mitre link : CVE-2009-1906

CVE.ORG link : CVE-2009-1906


JSON object : View

Products Affected

ibm

  • db2