Boletines de Vulnerabilidades

IBM Security Bulletin: IBM® DB2® LUW contains a denial of service vulnerability in ALTER MODULE statement handling. (CVE-2014-3094)


Información sobre el sistema

   
Software afectado IBM

Descripción

IBM DB2 is vulnerable to a stack buffer overflow, caused by improper bounds checking in the handling of the ALTER MODULE statement. CVE(s): CVE-2014-3094 Affected product(s) and affected version(s): All fix pack levels for IBM DB2 V9.7, V10.1 and V10.5 editions listed below and running on AIX, Linux, HP, Solaris or Windows are affected. IBM® DB2® Express Edition IBM® DB2® Workgroup Server Edition IBM® DB2® Enterprise Server Edition IBM® DB2® Advanced

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_db2_luw_contains_a_denial_of_service_vulnerability_in_alter_module_statement_handling_cve_2014_3094?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3094 ,CVE-2013-6371 ,CVE-2013-6954 ,CVE-2013-6629 ,CVE-2014-2421 ,CVE-2014-0453 ,CVE-2014-1876 ,CVE-2014-4244 ,CVE-2014-4263 and CVE-2014-0411.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-09-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT