Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
Patch Issued For DB2 Vulnerability

By Shawna McAlearney

Experts recommend that IBM DB2 users apply a patch for binary buffer-overflow vulnerabilities, which could allow an attacker to obtain complete control of a server database engine and full access to the database.

IBM issued a patch for two vulnerable setuid binaries, db2licm and db2dart, which run with elevated privileges on behalf of regular unprivileged operating system users. According to Core Security Technologies, which worked with IBM to create a patch, a default install will allow an attacker with system access to escalate privileges to the root account by providing a long command-line argument to the binaries.

IBM's flagship relational database, DB2, has a deployment base of an estimated 60 million users. It can be deployed in AIX, HP-UX, Linux, Solaris and Windows environments.

More information
Patch


Source: Security Wire Digest - Information Security Magazine
http://infosecuritymag.techtarget.com/ss/0,295812,sid6_iss101,00.html#news3

Related Content