CVE-2005-4869: Null Pointer Dereference
Published Dec 31, 2005
·Updated
The (1) tochar and (2) todate function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
Affected Software
1 affected component
IBM DB2=8.1
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Oct 7, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4869?
CVE-2005-4869 has a moderate severity level as it can lead to a denial of service due to application crashes.
2
How do I fix CVE-2005-4869?
To fix CVE-2005-4869, avoid using empty strings as the second parameter in the to_char and to_date functions.
3
Who is affected by CVE-2005-4869?
CVE-2005-4869 affects local users of IBM DB2 version 8.1.
4
What causes the vulnerability in CVE-2005-4869?
The vulnerability in CVE-2005-4869 is caused by a null pointer dereference when an empty string is passed as the second parameter.
5
Is CVE-2005-4869 exploitable remotely?
No, CVE-2005-4869 is not remotely exploitable as it requires local access to the IBM DB2 system.