CVE-2004-1372: Buffer Overflow
Published Sep 1, 2004
·Updated
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generatedistfile procedure.
Affected Software
4 affected components
IBM DB2 Universal Database=8.1
IBM DB2 Universal Database=7.1
IBM DB2 Universal Database=7.0
IBM DB2 Universal Database=7.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 1, 2004
CVE Published
04:00 AM
Jan 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1372?
CVE-2004-1372 is considered to have a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2004-1372?
To fix CVE-2004-1372, update IBM DB2 to the latest patched version that addresses the buffer overflow vulnerabilities.
3
What are the affected versions in CVE-2004-1372?
CVE-2004-1372 affects IBM DB2 versions 7.x and 8.1, specifically on Linux and AIX platforms.
4
Who can exploit CVE-2004-1372?
Local users with access to IBM DB2 can exploit CVE-2004-1372 to execute arbitrary code.
5
What functions are involved in CVE-2004-1372 vulnerability?
CVE-2004-1372 involves buffer overflows in the rec2xml function and the generate_distfile procedure in IBM DB2.