First published: Wed Apr 16 2008(Updated: )
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =8 | |
IBM DB2 Universal Database | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5758 has a severity rating that indicates a high risk due to the potential for arbitrary code execution.
To mitigate CVE-2007-5758, upgrade IBM DB2 Universal Database to version 9.5 Fix Pack 1, 9.1 Fix Pack 4a, or 8 FixPak 16 or later.
Local users of IBM DB2 Universal Database versions 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 are affected by CVE-2007-5758.
CVE-2007-5758 is caused by a stack-based buffer overflow in the db2dasrrm component due to a long DASPROF environment variable.
Exploitation of CVE-2007-5758 can be prevented by ensuring that software is updated to the latest secured versions as recommended.