Multiple IBM DB2 product stack buffer overflow vulnerabilities (CVE-2014-3094)
Release date:
Updated on: 2014-09-04
Affected Systems:
IBM DB2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69550
CVE (CAN) ID: CVE-2014-3094
IBM DB2 is a large commercial relational database system.
When IBM DB2 processes the alter module statement, the boundary is not correctly checked. The stack buffer overflow vulnerability exists in the implementation. Remote attackers can exploit this vulnerability to execute arbitrary code with the DB2 instance owner privilege.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://xforce.iss.net/xforce/xfdb/94260
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg21681631
Http://www.ibm.com/support/docview.wss? Uid = swg24038261
This article permanently updates the link address: