First published: Tue Mar 20 2012(Updated: )
Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.1 | |
IBM DB2 Universal Database | =9.1-fp1 | |
IBM DB2 Universal Database | =9.1-fp10 | |
IBM DB2 Universal Database | =9.1-fp11 | |
IBM DB2 Universal Database | =9.1-fp2 | |
IBM DB2 Universal Database | =9.1-fp2a | |
IBM DB2 Universal Database | =9.1-fp3 | |
IBM DB2 Universal Database | =9.1-fp3a | |
IBM DB2 Universal Database | =9.1-fp4 | |
IBM DB2 Universal Database | =9.1-fp4a | |
IBM DB2 Universal Database | =9.1-fp5 | |
IBM DB2 Universal Database | =9.1-fp6 | |
IBM DB2 Universal Database | =9.1-fp6a | |
IBM DB2 Universal Database | =9.1-fp7 | |
IBM DB2 Universal Database | =9.1-fp7a | |
IBM DB2 Universal Database | =9.1-fp8 | |
IBM DB2 Universal Database | =9.1-fp9 | |
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =9.5-fp1 | |
IBM DB2 Universal Database | =9.5-fp2 | |
IBM DB2 Universal Database | =9.5-fp2a | |
IBM DB2 Universal Database | =9.5-fp3 | |
IBM DB2 Universal Database | =9.5-fp3a | |
IBM DB2 Universal Database | =9.5-fp3b | |
IBM DB2 Universal Database | =9.5-fp4 | |
IBM DB2 Universal Database | =9.5-fp4a | |
IBM DB2 Universal Database | =9.5-fp5 | |
IBM DB2 Universal Database | =9.5-fp6 | |
IBM DB2 Universal Database | =9.5-fp6a | |
IBM DB2 Universal Database | =9.5-fp7 | |
IBM DB2 Universal Database | =9.5-fp8 | |
IBM DB2 Universal Database | =9.7 | |
IBM DB2 Universal Database | =9.7-fp1 | |
IBM DB2 Universal Database | =9.7-fp2 | |
IBM DB2 Universal Database | =9.7-fp3 | |
IBM DB2 Universal Database | =9.7-fp3a | |
IBM DB2 Universal Database | =9.7-fp4 | |
IBM DB2 Universal Database | =9.7-fp5 | |
IBM AIX | ||
Linux Kernel | ||
SunOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0711 has a CVSS score of 7.5, indicating it is a high severity vulnerability.
To mitigate CVE-2012-0711, upgrade your IBM DB2 software to the latest fix pack available.
CVE-2012-0711 affects DB2 versions 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5.
Yes, CVE-2012-0711 can be exploited remotely by attackers to execute arbitrary code.
CVE-2012-0711 is classified as a heap-based buffer overflow due to an integer signedness error.