The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:09
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT - Patch | |
References | () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT - | |
References | () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT - | |
References | () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v97/APARLIST.TXT - | |
References | () http://secunia.com/advisories/37759 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IC64702 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1LI72709 - Exploit, Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1LI74500 - Exploit, Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1LI74504 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21293566 - Patch, Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21412902 - | |
References | () http://www.securityfocus.com/bid/37332 - | |
References | () http://www.vupen.com/english/advisories/2009/3520 - Vendor Advisory |
Information
Published : 2009-12-16 18:30
Updated : 2024-11-21 01:09
NVD link : CVE-2009-4325
Mitre link : CVE-2009-4325
CVE.ORG link : CVE-2009-4325
JSON object : View
Products Affected
ibm
- db2
CWE
CWE-20
Improper Input Validation