First published: Tue Feb 12 2008(Updated: )
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | <=9.0 | |
IBM Db2 | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3676 has a high severity level due to its potential for remote denial of service and arbitrary code execution.
To fix CVE-2007-3676, upgrade to IBM DB2 UDB Administration Server version 8 Fix Pack 16 or 9 Fix Pack 4 or later.
CVE-2007-3676 affects IBM DB2 UDB Administration Server versions prior to Fix Pack 16 for 8.0 and Fix Pack 4 for 9.0.
CVE-2007-3676 can be exploited through modified pointer values in remote administration requests, leading to system crashes.
While CVE-2007-3676 primarily leads to denial of service, it could potentially result in data loss if exploited during sensitive operations.