CVE-2007-3676
iDEFENSE Security Advisory 2008-02-07.2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
El Servidor de Administración (DAS) de IBM DB2 Universal Database (UDB) en versión 8 anterior al Fix Pack 16 y versión 9 anterior a Fix Pack 4, permite a atacantes remotos provocar una denegación de servicio (caída) y posiblemente ejecutar código de su elección a través de valores del puntero modificados en solicitudes de administración remota no especificadas; esto provoca una corrupción de memoria u otro acceso no válido a memoria. NOTA: este podría ser el mismo problema que CVE-2008-0698
Remote exploitation of a memory corruption vulnerability within version 9.1 of IBM Corp.'s DB2 Universal Database Administration Server (DAS) allows attackers to crash the service or potentially execute arbitrary code in the context of the affected service. iDefense has confirmed the existence of this vulnerability in the DAS (db2dassrm) as included with DB2 9.1 with Fix Pack 2 for both Linux and Windows platforms. Previous versions, as well as builds for other platforms, are suspected to be vulnerable.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-10 CVE Reserved
- 2008-02-08 CVE Published
- 2024-09-16 CVE Updated
- 2025-06-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1019318 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=654 | 2008-09-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | <= 8.0 Search vendor "Ibm" for product "Db2" and version " <= 8.0" | fix_pack15 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Db2 Search vendor "Ibm" for product "Db2" | <= 9.0 Search vendor "Ibm" for product "Db2" and version " <= 9.0" | fix_pack3a |
Affected
|