#VU12310 Integer overflow in IBM DB2


Published: 2018-05-01

Vulnerability identifier: #VU12310

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2018-1427

CWE-ID: CWE-190

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
IBM DB2
Server applications / Database software

Vendor: IBM Corporation

Description
The vulnerability allows a local unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to IBM GSKit contains several environment variables. A local attacker can cause the service to crash.

Mitigation
Install update from vendor's website.

Vulnerable software versions

IBM DB2: 11.1.0.0, 10.5.0.0, 10.1.0.0, 9.7.0.0


CPE

External links
http://exchange.xforce.ibmcloud.com/vulnerabilities/139072


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability