CVE-2007-1087: Buffer Overflow
Published Feb 23, 2007
·Updated
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
Affected Software
20 affected components
IBM DB2=8.0
IBM DB2=8.0-fp13
IBM DB2=8.0-fp14
IBM DB2=8.0-fp8
IBM DB2=8.0-fp9
IBM DB2=8.1
IBM DB2=8.1-fp13
IBM DB2=8.1-fp14
IBM DB2=8.1.4
IBM DB2=8.1.5
IBM DB2=8.1.6
IBM DB2=8.1.6c
IBM DB2=8.1.7
IBM DB2=8.1.7b
IBM DB2=8.1.8
IBM DB2=8.1.8a
IBM DB2=8.1.9
IBM DB2=8.1.9a
IBM DB2=9.1
IBM DB2=9.1-fp1
Remediation
Patch Available
Patch Available
Event History
Feb 23, 2007
CVE Published
10:28 PM
Feb 24, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1087?
CVE-2007-1087 is considered critical due to its potential for local users to execute arbitrary code.
2
How do I fix CVE-2007-1087?
To fix CVE-2007-1087, upgrade IBM DB2 to version 8.1 FixPak 15 or 9.1 Fix Pack 2 or higher.
3
Who is affected by CVE-2007-1087?
CVE-2007-1087 affects IBM DB2 versions 8.x prior to FixPak 15 and 9.1 prior to Fix Pack 2.
4
What type of vulnerability is CVE-2007-1087?
CVE-2007-1087 is a heap-based buffer overflow vulnerability.
5
Can CVE-2007-1087 be exploited remotely?
CVE-2007-1087 is not remotely exploitable; it requires local access to the affected system.