First published: Fri Jan 16 2009(Updated: )
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-ga | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-0172 is moderate, as it can lead to a denial of service through an infinite loop.
To fix CVE-2009-0172, apply the latest fix pack for IBM DB2 that addresses this vulnerability.
CVE-2009-0172 affects IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a.
CVE-2009-0172 is an unspecified vulnerability that allows remote attackers to create a denial of service condition.
Yes, CVE-2009-0172 can be exploited remotely through a crafted CONNECT data stream.