Secunia Security Advisory - Some vulnerabilities have been reported in DB2, where some have an unknown impact and others can be exploited by malicious people to cause a DoS.
da504885a0c6b85188eb2784f090c94199fe75f6ea9f0abdd295cc0a2d02ff7a
----------------------------------------------------------------------
We have updated our website, enjoy!
http://secunia.com/
----------------------------------------------------------------------
TITLE:
IBM DB2 Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA31787
VERIFY ADVISORY:
http://secunia.com/advisories/31787/
CRITICAL:
Moderately critical
IMPACT:
Unknown, DoS
WHERE:
>From remote
SOFTWARE:
DB2 Universal Database 8.x
http://secunia.com/product/857/
DESCRIPTION:
Some vulnerabilities have been reported in DB2, where some have an
unknown impact and others can be exploited by malicious people to
cause a DoS.
1) An unspecified error related to the processing of CONNECT and
ATTACH requests can be exploited to cause a DoS.
2) An unspecified error exists related to the DB2FMP process. No
further information is currently available.
This is related to vulnerability #3 in:
SA29784
3) An unspecified error in the DB2JDS service can be exploited to
cause a crash via specially crafted packets.
The vulnerabilities are reported in IBM DB2 version 8 prior to Fixpak
17.
SOLUTION:
Update to Fixpak 17.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
IBM (IZ08134, IZ20350, JR29274):
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT
OTHER REFERENCES:
SA29784:
http://secunia.com/advisories/29784/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------