CVE-2005-4863: Buffer Overflow
Published Dec 31, 2005
·Updated
Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.
Affected Software
16 affected components
IBM DB2 Universal Database=7.0
IBM DB2 Universal Database=7.0
IBM DB2 Universal Database=7.0
IBM DB2 Universal Database=7.0
IBM DB2 Universal Database=7.1
IBM DB2 Universal Database=7.1
IBM DB2 Universal Database=7.1
IBM DB2 Universal Database=7.1
IBM DB2 Universal Database=7.2
IBM DB2 Universal Database=7.2
IBM DB2 Universal Database=7.2
IBM DB2 Universal Database=7.2
IBM DB2 Universal Database=8.1
IBM DB2 Universal Database=8.1
IBM DB2 Universal Database=8.1
IBM DB2 Universal Database=8.1
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Oct 7, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4863?
CVE-2005-4863 has a high severity rating due to its potential for local users to execute arbitrary code.
2
How do I fix CVE-2005-4863?
To fix CVE-2005-4863, apply the relevant patches provided by IBM for affected versions of DB2.
3
What versions of IBM DB2 are affected by CVE-2005-4863?
CVE-2005-4863 affects IBM DB2 versions 7.x and 8.1 across multiple operating systems including AIX, Linux, Solaris, and HP-UX.
4
Can CVE-2005-4863 be exploited remotely?
No, exploitation of CVE-2005-4863 requires local access to the affected system.
5
What type of vulnerability is CVE-2005-4863?
CVE-2005-4863 is classified as a stack-based buffer overflow vulnerability.