CVE-2008-3958: High severity ibm db2 universal database vulnerability
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3958?
The severity of CVE-2008-3958 is classified as high due to the potential for remote denial of service attacks.
How do I fix CVE-2008-3958?
To fix CVE-2008-3958, upgrade IBM DB2 UDB to Fixpak 17 or later.
What versions of IBM DB2 are affected by CVE-2008-3958?
CVE-2008-3958 affects IBM DB2 UDB version 8 before Fixpak 17.
Can CVE-2008-3958 lead to data loss?
CVE-2008-3958 primarily causes a denial of service and does not directly lead to data loss but may disrupt database operations.
Is CVE-2008-3958 exploitable remotely?
Yes, CVE-2008-3958 can be exploited remotely through crafted CONNECT/ATTACH data streams.