MEDIUM
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function
Published Jan 28, 2010
6.5
MEDIUMCVSS 2.0
EPSS 7.52%
Description
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.
Affected products
No data.
OR
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.5
- 9.5
- 9.5
- 9.5
- 9.5
- 9.5
- 9.5
- 9.5
- 9.5
- 9.5
- 9.7
- 9.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT x_refsource_CONFIRM
- http://intevydis.blogspot.com/2010/01/ibm-db2-97-heap-overflow.html x_refsource_MISCExploit
- http://securitytracker.com/id?1023509 vdb-entryx_refsource_SECTRACK
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65922 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65933 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC65935 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg21426108 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21432298 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/37976 vdb-entryx_refsource_BIDExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55899 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14518 vdb-entrysignaturex_refsource_OVAL
| Link | Providers | Tags |
|---|---|---|
| ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT | x_refsource_CONFIRM | |
| http://intevydis.blogspot.com/2010/01/ibm-db2-97-heap-overflow.html | x_refsource_MISCExploit | |
| http://securitytracker.com/id?1023509 | vdb-entryx_refsource_SECTRACK | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1IC65922 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1IC65933 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1IC65935 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www-01.ibm.com/support/docview.wss?uid=swg21426108 | x_refsource_CONFIRM | |
| http://www-01.ibm.com/support/docview.wss?uid=swg21432298 | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/37976 | vdb-entryx_refsource_BIDExploit | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/55899 | vdb-entryx_refsource_XF | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14518 | vdb-entrysignaturex_refsource_OVAL |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 28, 2010
Updated Aug 7, 2024
Reserved Jan 28, 2010
Link CVE-2010-0462
CISA Vulnrichment
Updated n/a