CVE-2019-4014: Buffer Overflow
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4014?
CVE-2019-4014 has a high severity rating due to the potential for authenticated local attackers to execute arbitrary code as root.
How do I fix CVE-2019-4014?
To address CVE-2019-4014, users should upgrade to a fixed version of IBM DB2 that addresses this buffer overflow vulnerability.
What versions are affected by CVE-2019-4014?
CVE-2019-4014 affects IBM DB2 versions 9.7, 10.1, 10.5, and 11.1, including various builds of these versions.
Are there any workarounds for CVE-2019-4014?
Currently, there are no known workarounds for CVE-2019-4014, so upgrading is the recommended action.
Is CVE-2019-4014 a remote attack vulnerability?
No, CVE-2019-4014 requires local authentication, limiting the potential for remote exploitation.