CVE-2006-3066: Buffer Overflow
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3066?
CVE-2006-3066 is classified as a high severity vulnerability due to the potential for denial of service attacks.
How do I fix CVE-2006-3066?
To fix CVE-2006-3066, upgrade IBM DB2 Universal Database to version 8.1 FixPak 12 or later.
What versions of IBM DB2 Universal Database are affected by CVE-2006-3066?
CVE-2006-3066 affects various versions of IBM DB2 Universal Database prior to 8.1 FixPak 12, including versions 8.0 to 8.1.9.
What type of attack does CVE-2006-3066 enable?
CVE-2006-3066 enables remote attackers to perform denial of service attacks by crashing the application.
Is there a known exploit for CVE-2006-3066?
Yes, CVE-2006-3066 is known to be exploited by sending specially crafted messages that trigger the buffer overflow.