Release date:
Updated on:
Affected Systems:
IBM DB2 9.7 Fix Pack 6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53873
Cve id: CVE-2012-2180
IBM DB2 is a large-scale commercial relational database system for e-commerce, commercial information, content management, customer relationship management, and other applications, it can run on AIX, HP-UX, Linux, Solaris, Windows, and other systems.
The link feature in DRDA modules of IBM DB2 9.7 and 9.8 earlier than FP5 allows remote attackers to cause denial of service (empty pointer reference, resource consumption, or program crash) through specially crafted requests).
<* Source: vendor
Link: http://www-01.ibm.com/support/docview.wss? Uid = swg1IC82234
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
For this reason, IBM has released a Security Bulletin (IC82234) and corresponding patches:
IC82234: SECURITY: DB2 denial of service vulnerability in the drda component (CVE-2012-2180 ).
Link: http://www-01.ibm.com/support/docview.wss? Uid = swg1IC82234