First published: Mon Jun 19 2006(Updated: )
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =8.1.4 | |
IBM DB2 Universal Database | =8.1.6 | |
IBM DB2 Universal Database | =8.1 | |
IBM DB2 Universal Database | =8.1.8a | |
IBM DB2 Universal Database | =8.1.6c | |
IBM DB2 Universal Database | =8.1.8 | |
IBM DB2 Universal Database | =8.1.7b | |
IBM DB2 Universal Database | =8.0 | |
IBM DB2 Universal Database | =8.1.5 | |
IBM DB2 Universal Database | =8.1.7 | |
IBM DB2 Universal Database | =8.1.9a | |
IBM DB2 Universal Database | =8.1.9 | |
IBM DB2 Universal Database | <=8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3066 is classified as a high severity vulnerability due to the potential for denial of service attacks.
To fix CVE-2006-3066, upgrade IBM DB2 Universal Database to version 8.1 FixPak 12 or later.
CVE-2006-3066 affects various versions of IBM DB2 Universal Database prior to 8.1 FixPak 12, including versions 8.0 to 8.1.9.
CVE-2006-3066 enables remote attackers to perform denial of service attacks by crashing the application.
Yes, CVE-2006-3066 is known to be exploited by sending specially crafted messages that trigger the buffer overflow.