Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
DB2 Vulnerability Allows Hackers To Gain Complete Control


Core Security Technologies plans on Thursday to release a warning about a vulnerability in the IBM DB2 database that could allow an attacker to gain complete control of a server DB2 database engine and full access to the information stored in the database.

Core Security says it has been working with IBM to develop a patch for the problem.

The vulnerability affects two setuid binaries, db2licm and db2dart, which run with elevated privileges on behalf of regular, unprivileged users. Both utilities are vulnerable to buffer overflow that allows a local attacker to execute arbitrary code on the vulnerable system with privileges of the root user. For more information, see the Core Security Web site, and for patch information, see the IBM Web site.



Source: InternetWeek.com
http://www.internetweek.com/breakingNews/showArticle.jhtml;jsessionid=TJE0IEWY2BBIKQSNDBGCKHQ?articleID=14800254

Related Content