Email us! Subscribe to Liquidmatrix!

IBM DB2 Buffer Overflow

db2.JPG

Only a week late noticing this one. Sheesh. Turns out that there is a buffer overflow in DB2. Specifically in “sysproc.auth_list_groups_for_authid”.

From the AppSecInc advisory:

Details:
Buffer overflow on sysproc.auth_list_groups_for_authid function.
By passing an overly long value of more then 40-bytes to the auth_list_groups_for_authid function,
a stack-based buffer can be overflowen.

OS:
Windows 2003 sp1

Install options:
DB2 Installed with all defaults but with Notifications disabled

Impact:
An attacker can use this to cause a denial of service or take complete control of an affected system.

Vendor Status:
Vendor was contacted and a patch was released.

Article Link

IBM DB2 Page

Tags: ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • IBM Lotus Domino XSS and Buffer Overflow Vulnerabilities
  • WinDVD ActiveX Control Buffer Overflow
  • Snort Buffer Overflow
  • Microsoft Windows Vector Markup Language Buffer Overflow
  • Ask Toolbar ActiveX Control Buffer Overflow
  • Leave a Comment