CVE-2007-4273: Medium severity IBM DB2 Universal Database vulnerability
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRCLOGFILE environment variable in db2licd (db2licm).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4273?
CVE-2007-4273 is considered a medium severity vulnerability due to its potential to allow local users to execute arbitrary code.
How do I fix CVE-2007-4273?
To fix CVE-2007-4273, apply Fixpak 15 for DB2 UDB 8 or Fixpak 3 for DB2 UDB 9.1.
Who is affected by CVE-2007-4273?
CVE-2007-4273 affects local users of IBM DB2 Universal Database 8 before Fixpak 15 and 9.1 before Fixpak 3.
What is a format string attack in the context of CVE-2007-4273?
A format string attack in CVE-2007-4273 allows an attacker to manipulate the output of a program by using crafted localized message files.
Can CVE-2007-4273 be exploited remotely?
CVE-2007-4273 is not a remote vulnerability; it requires local access to exploit.