First published: Mon Aug 21 2006(Updated: )
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =8.1.8 | |
IBM Db2 | =8.1.8 | |
IBM Db2 | =8.1.8 | |
IBM Db2 | =8.1.8a | |
IBM Db2 | =8.1.7b | |
IBM Db2 | =8.1.9a | |
IBM Db2 | =8.1.7 | |
IBM Db2 | =8.1.6 | |
IBM Db2 | =8.12 | |
IBM Db2 | =8.1.8a | |
IBM Db2 | =8.1.4 | |
IBM Db2 | =8.1.8 | |
IBM Db2 | =8.1.9 | |
IBM Db2 | =8.1.5 | |
IBM Db2 | =8.0 | |
IBM Db2 | =8.1.7 | |
IBM Db2 | =8.0 | |
IBM Db2 | =8.1.5 | |
IBM Db2 | =8.1.6c | |
IBM Db2 | =8.12 | |
IBM Db2 | =8.1.8 | |
IBM Db2 | =8.2 | |
IBM Db2 | =8.12 | |
IBM Db2 | =8.1.7b | |
IBM Db2 | =8.1 | |
IBM Db2 | =8.1.6c | |
IBM Db2 | =8.1.6c | |
IBM Db2 | =8.1.5 | |
IBM Db2 | =8.1.9 | |
IBM Db2 | =8.1.4 | |
IBM Db2 | =8.10 | |
IBM Db2 | =8.1.9 | |
IBM Db2 | =8.1.4 | |
IBM Db2 | =8.1.9a | |
IBM Db2 | =8.1.7 | |
IBM Db2 | =8.1.9a | |
IBM Db2 | =8.1 | |
IBM Db2 | =8.1 | |
IBM Db2 | =8.1.8a | |
IBM Db2 | =8.1.4 | |
IBM Db2 | =8.1 | |
IBM Db2 | =8.0 | |
IBM Db2 | =8.1.6 | |
IBM Db2 | =8.10 | |
IBM Db2 | =8.1.5 | |
IBM Db2 | =8.1.7b | |
IBM Db2 | =8.1.7 | |
IBM Db2 | =8.1.6c | |
IBM Db2 | =8.1.9a | |
IBM Db2 | =8.1.6 | |
IBM Db2 | =8.1.9 | |
IBM Db2 | =8.1.7b | |
IBM Db2 | =8.1.8a | |
IBM Db2 | =8.1.6 | |
IBM Db2 | =8.1.8a | |
IBM Db2 | =8.1 | |
IBM Db2 | =8.1.6c | |
IBM Db2 | =8.1.7 | |
IBM Db2 | =8.1.9a | |
IBM Db2 | =8.1.5 | |
IBM Db2 | =8.10 | |
IBM Db2 | =8.1.4 | |
IBM Db2 | =8.1.9 | |
IBM Db2 | =8.1.6 | |
IBM Db2 | =8.1.7b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4257 has a moderate severity rating due to its potential to cause denial of service.
To fix CVE-2006-4257, you should upgrade IBM DB2 Universal Database to version 8.1 FixPak 13 or later.
CVE-2006-4257 affects IBM DB2 Universal Database versions before 8.1 FixPak 13 across various operating systems.
Exploitation of CVE-2006-4257 can occur by sending malformed ACCSEC commands or crafted SQLJRA packets during the CONNECT process.
Yes, CVE-2006-4257 can be exploited by remote authenticated users.