Boletines de Vulnerabilidades

IBM Security Bulletin: IBM® DB2® LUW is affected by the JSON-C vulnerability (CVE-2013-6371)


Información sobre el sistema

   
Software afectado IBM

Descripción

IBM® DB2® LUW is affected by a denial of service vulnerability in JavaScript Object Notation (JSON-C), caused by an error in the hash function during string parsing. A remote, unauthorized user could exploit this vulnerability to consume all available CPU resources. CVE(s): CVE-2013-6371 Affected product(s) and affected version(s): IBM DB2 V10.5 editions listed below and running on AIX, Linux, HP, Solaris or Windows are affected. IBM® DB2® Express Edition IBM®

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_db2_luw_is_affected_by_the_json_c_vulnerability_cve_2013_6371?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2013-6371 ,CVE-2014-3075 ,CVE-2014-0094 and CVE-2014-0411.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-09-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT