CVE-2012-0711
Publication date 20 March 2012
Last updated 24 July 2024
Ubuntu priority
Description
Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| db2exc | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
Notes
Patch details
| Package | Patch details |
|---|---|
| db2exc |
References
Other references
- http://xforce.iss.net/xforce/xfdb/73495
- http://www-01.ibm.com/support/docview.wss?uid=swg21588093
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC80729
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC80728
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC80561
- https://www.cve.org/CVERecord?id=CVE-2012-0711