CVE-2017-1297: Buffer Overflow
Published Jun 27, 2017
·Updated
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
Affected Software
38 affected components
IBM Data Server Client
IBM Data Server Driver For Odbc And Cli
IBM Data Server Driver Package
IBM Data Server Runtime Client
IBM DB2=9.7
IBM DB2=9.7
IBM DB2=9.7
IBM DB2=9.7
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=10.5
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
IBM DB2=11.1
IBM DB2 Connect=9.7
IBM DB2 Connect=9.7
IBM DB2 Connect=9.7
IBM DB2 Connect=10.1
IBM DB2 Connect=10.1
IBM DB2 Connect=10.1
IBM DB2 Connect=10.5
IBM DB2 Connect=10.5
IBM DB2 Connect=10.5
IBM DB2 Connect=11.1.0.0
IBM DB2 Connect=11.1.0.0
IBM DB2 Connect=11.1.0.0
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Jun 27, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1297?
The severity of CVE-2017-1297 is classified as high due to the potential for local attackers to execute arbitrary code.
2
How do I fix CVE-2017-1297?
To fix CVE-2017-1297, you should apply the latest patches provided by IBM for the affected versions of DB2.
3
Which versions of DB2 are affected by CVE-2017-1297?
CVE-2017-1297 affects IBM DB2 versions 9.2, 9.7, 10.1, 10.5, and 11.1.
4
Who can exploit CVE-2017-1297?
CVE-2017-1297 can be exploited by local attackers with access to the vulnerable system.
5
What type of vulnerability is CVE-2017-1297?
CVE-2017-1297 is a stack-based buffer overflow vulnerability caused by improper bounds checking.