First published: Wed Oct 22 2008(Updated: )
Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Db2 | <=9.1 | |
IBM Db2 | =9.1 | |
IBM Db2 | =9.1-fp1 | |
IBM Db2 | =9.1-fp2 | |
IBM Db2 | =9.1-fp3 | |
IBM Db2 | =9.1-fp3a | |
IBM Db2 | =9.1-fp4 | |
IBM Db2 | =9.1-fp4a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4691 has not been assigned a severity rating, but it can cause denial of service via a segmentation violation.
To fix CVE-2008-4691, upgrade IBM DB2 to version 9.1 FP6 or later.
CVE-2008-4691 affects IBM DB2 versions before 9.1 FP6 including 9.1 and its fix packs 1 through 5.
CVE-2008-4691 allows attackers to cause a denial of service on affected DB2 servers.
There are no known workarounds for CVE-2008-4691; upgrading to a patched version is recommended.