Integer overflow in IBM DB2 - CVE-2018-1427

 

Integer overflow in IBM DB2 - CVE-2018-1427

Published: May 1, 2018


Vulnerability identifier: #VU12310
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1427
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to IBM GSKit contains several environment variables. A local attacker can cause the service to crash.

Affected software

IBM DB2
Planning Analytics Local
IBM Cognos Analytics
IBM Algo One Core
IBM Cognos Controller
Security Network Protection
IBM Tivoli Directory Server
IBM MQ
Tivoli Network Manager IP Edition

How to mitigate CVE-2018-1427

Install update from vendor's website.

IBM Cognos Analytics - update to 11.0.13
Tivoli Network Manager IP Edition - addressed in versions 3.9.0.132, 4.1.1.49, 4.2.0.5

External References

Related Security Bulletins