CVE-2013-3475: Buffer Overflow
Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3475?
CVE-2013-3475 is classified as a high severity vulnerability due to its potential for privilege escalation.
How can I mitigate CVE-2013-3475?
Mitigation for CVE-2013-3475 involves applying the latest patches and updates provided by IBM for affected DB2 and DB2 Connect versions.
Who is affected by CVE-2013-3475?
CVE-2013-3475 affects users of IBM DB2 versions 9.1, 9.5, 9.7, 9.8, and 10.1, as well as IBM DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1.
What kind of attacks can exploit CVE-2013-3475?
CVE-2013-3475 can be exploited through local attacks that leverage the stack-based buffer overflow to gain unauthorized privileges.
Is there a fix available for CVE-2013-3475?
Yes, IBM has released fixes in the form of patches for CVE-2013-3475 which should be applied to affected systems.