CVE-2008-1966: Buffer Overflow
Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVEJAR procedure with a crafted parameter, related to (a) sqlj.installjar and (b) sqlj.replacejar.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1966?
CVE-2008-1966 is rated as a medium severity vulnerability due to its potential to cause a denial of service through crashes.
How do I fix CVE-2008-1966?
To fix CVE-2008-1966, you should apply the latest fix pack or update for IBM DB2 versions affected by this vulnerability.
Which versions of IBM DB2 are affected by CVE-2008-1966?
CVE-2008-1966 affects IBM DB2 versions 8 before FP16, 9.1 before FP4a, and 9.5 before FP1.
What type of vulnerability is CVE-2008-1966?
CVE-2008-1966 is a buffer overflow vulnerability that can lead to remote denial of service.
Can CVE-2008-1966 be exploited remotely?
Yes, CVE-2008-1966 can be exploited by remote authenticated users to cause denial of service.