First published: Wed Jun 05 2013(Updated: )
Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Db2 | =9.1 | |
Ibm Db2 | =9.5 | |
Ibm Db2 | =9.7 | |
Ibm Db2 | =9.8 | |
Ibm Db2 | =10.1 | |
IBM DB2 Connect | =9.1 | |
IBM DB2 Connect | =9.5 | |
IBM DB2 Connect | =9.7 | |
IBM DB2 Connect | =9.8 | |
IBM DB2 Connect | =10.1 | |
IBM Smart Analytics System 7600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3475 is classified as a high severity vulnerability due to its potential for privilege escalation.
Mitigation for CVE-2013-3475 involves applying the latest patches and updates provided by IBM for affected DB2 and DB2 Connect versions.
CVE-2013-3475 affects users of IBM DB2 versions 9.1, 9.5, 9.7, 9.8, and 10.1, as well as IBM DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1.
CVE-2013-3475 can be exploited through local attacks that leverage the stack-based buffer overflow to gain unauthorized privileges.
Yes, IBM has released fixes in the form of patches for CVE-2013-3475 which should be applied to affected systems.