First published: Fri Feb 23 2007(Updated: )
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | =8.0 | |
IBM Db2 | =8.0-fp13 | |
IBM Db2 | =8.0-fp14 | |
IBM Db2 | =8.0-fp8 | |
IBM Db2 | =8.0-fp9 | |
IBM Db2 | =8.1 | |
IBM Db2 | =8.1-fp13 | |
IBM Db2 | =8.1-fp14 | |
IBM Db2 | =8.1.4 | |
IBM Db2 | =8.1.5 | |
IBM Db2 | =8.1.6 | |
IBM Db2 | =8.1.6c | |
IBM Db2 | =8.1.7 | |
IBM Db2 | =8.1.7b | |
IBM Db2 | =8.1.8 | |
IBM Db2 | =8.1.8a | |
IBM Db2 | =8.1.9 | |
IBM Db2 | =8.1.9a | |
IBM Db2 | =9.1 | |
IBM Db2 | =9.1-fp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1087 is considered critical due to its potential for local users to execute arbitrary code.
To fix CVE-2007-1087, upgrade IBM DB2 to version 8.1 FixPak 15 or 9.1 Fix Pack 2 or higher.
CVE-2007-1087 affects IBM DB2 versions 8.x prior to FixPak 15 and 9.1 prior to Fix Pack 2.
CVE-2007-1087 is a heap-based buffer overflow vulnerability.
CVE-2007-1087 is not remotely exploitable; it requires local access to the affected system.