CVE-2003-0837: Buffer Overflow
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DB2 Universal Data Base 7.2 for Windowsto a version that resolves this vulnerability.Fixed in Fixpak 10a
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0837?
CVE-2003-0837 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2003-0837?
To mitigate CVE-2003-0837, install Fixpak 10a or later for IBM DB2 Universal Database 7.2.
Who is affected by CVE-2003-0837?
CVE-2003-0837 affects users of IBM DB2 Universal Database 7.2 for Windows prior to Fixpak 10a.
What causes CVE-2003-0837?
CVE-2003-0837 is caused by a stack-based buffer overflow in the INVOKE command functionality.
Can CVE-2003-0837 be exploited remotely?
Yes, CVE-2003-0837 can be exploited by attackers with 'Connect' privileges remotely.