CVE-2008-3959: Medium severity ibm db2 universal database vulnerability
IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3959?
CVE-2008-3959 is classified as a denial of service vulnerability.
How do I fix CVE-2008-3959?
To fix CVE-2008-3959, you should apply the latest FixPak for your version of IBM DB2 UDB.
What versions of IBM DB2 UDB are affected by CVE-2008-3959?
CVE-2008-3959 affects IBM DB2 UDB versions 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a.
What kind of attack can exploit CVE-2008-3959?
An attacker can exploit CVE-2008-3959 by sending a crafted SQLJRA packet that simulates a V7 client connect/attach request.
What are the consequences of CVE-2008-3959?
Exploitation of CVE-2008-3959 can lead to a crash of the DB2 instance, resulting in a denial of service.