CVE-2018-1897: Buffer Overflow
Published Nov 30, 2018
·Updated
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462.
Affected Software
6 affected components
IBM DB2=9.7
IBM DB2=10.1
IBM DB2=10.5
IBM DB2=11.1
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Nov 30, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1897?
CVE-2018-1897 is classified as critical due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2018-1897?
To remediate CVE-2018-1897, upgrade to a patched version of IBM DB2 that addresses the stack buffer overflow vulnerability.
3
Which versions of IBM DB2 are affected by CVE-2018-1897?
CVE-2018-1897 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1.
4
What is the primary cause of CVE-2018-1897?
CVE-2018-1897 is caused by improper bounds checking in the db2pdcfg component of IBM DB2.
5
Can CVE-2018-1897 be exploited remotely?
Yes, CVE-2018-1897 can be exploited remotely by an attacker to execute arbitrary code.