The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Db2 | Ibm | 8.1 (including) | 8.1 (including) |