CVE Vulnerabilities

CVE-2009-1906

Published: Jun 03, 2009 | Modified: Jun 10, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.

Affected Software

Name Vendor Start Version End Version
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.5 9.5
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.1 9.1
Db2 Ibm 9.5 9.5
Db2 Ibm 9.5 9.5

References