First published: Fri Aug 20 2004(Updated: )
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1051 is considered a high severity vulnerability due to its potential to allow arbitrary code execution by local users.
To fix CVE-2003-1051, upgrade to a patched version of IBM DB2 Universal Database, specifically targeting versions later than 8.1.
CVE-2003-1051 affects local users of IBM DB2 Universal Database 8.1 who can access the command line tools.
The impact of CVE-2003-1051 allows local users to execute arbitrary commands, potentially compromising the integrity and security of the system.
A potential workaround for CVE-2003-1051 includes restricting access to the affected command line tools to trusted users only.