Release date:
Updated on:
Affected Systems:
IBM solidDB 6.5.0.3
IBM solidDB 6.5 FP 7
IBM solidDB 6.5 FP 6
IBM solidDB 6.5 FP 3
IBM solidDB 6.5 FP 2
IBM WebSphere 6.5
IBM solidDB 6.30.0.37
IBM solidDB 6.30.0.33
IBM solidDB 6.0.1068
IBM solidDB 6.0.10. 18
IBM solidDB 4.5.181
IBM solidDB 4.5.180
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47584
Cve id: CVE-2011-1208
The IBM solidDB product uses the memory-based relational database technology, providing an extremely high speed, 10 times faster than traditional hard disk-based databases. Using familiar SQL languages, solidDB can execute millions of transactions per second, and the response time can be calculated in microseconds.
Multiple Denial-of-Service vulnerabilities exist in the IBM solidDB implementation "rpc_test_svc" command. Remote attackers can exploit these vulnerabilities to cause the affected applications to crash and DOS legitimate users.
The Worker Process crashes after referencing a null pointer.
<* Source: Tenable Network Security (http://www.tenablesecurity.com /)
Link: http://www.zerodayinitiative.com/advisories/ZDI-11-142/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/