First published: Thu Aug 28 2008(Updated: )
Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3854 is considered to have a high severity due to potential remote denial of service attacks.
To fix CVE-2008-3854, upgrade IBM DB2 to version 9.1 Fixpak 5 or 9.5 Fixpak 1 or later.
The affected versions of IBM DB2 in CVE-2008-3854 include versions 9.1 before Fixpak 5 and 9.5 before Fixpak 1.
While CVE-2008-3854 primarily allows for denial of service, an attacker could use it as a vector to exploit further vulnerabilities.
CVE-2008-3854 facilitates remote denial of service attacks through multiple stack-based buffer overflows.