
By Shawna McAlearney
Experts recommend that IBM DB2 users apply a patch for binary buffer-overflow vulnerabilities, which could allow an attacker to obtain complete control of a server database engine and full access to the database.
IBM issued a patch for two vulnerable setuid binaries, db2licm and db2dart, which run with elevated privileges on behalf of regular unprivileged operating system users. According to Core Security Technologies, which worked with IBM to create a patch, a default install will allow an attacker with system access to escalate privileges to the root account by providing a long command-line argument to the binaries.
IBM's flagship relational database, DB2, has a deployment base of an estimated 60 million users. It can be deployed in AIX, HP-UX, Linux, Solaris and Windows environments.
More information
Patch
Source: Security Wire Digest - Information Security Magazine
http://infosecuritymag.techtarget.com/ss/0,295812,











