First published: Thu Aug 28 2008(Updated: )
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3853 is critical due to its potential to allow remote code execution and denial of service.
You can fix CVE-2008-3853 by upgrading to IBM DB2 version 9.1 FP4 or later, or 9.5 FP1 or later.
CVE-2008-3853 is caused by a buffer overflow in the DAS server program of IBM DB2.
Yes, CVE-2008-3853 can be exploited remotely, allowing attackers to affect the DB2 server.
IBM DB2 versions 9.1 before FP4 and 9.5 before FP1 are affected by CVE-2008-3853.