CVE-2012-2180

Priority
Medium
Description
The chaining functionality in the Distributed Relational Database
Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5
allows remote attackers to cause a denial of service (NULL pointer
dereference, and resource consumption or daemon crash) via a crafted
request.
References
Notes
jdstrand> contacted bizdev on 2012-06-21
tyhicks> Fixed in 9.7 FP6
Assigned-to
SpamapS
Package
Upstream:released (9.7 FP6)
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):needed
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Patches:
Upstream:http://www-01.ibm.com/support/docview.wss?uid=swg24032754
Package
Upstream:released (9.7 FP6)
Ubuntu 8.04 LTS (Hardy Heron):ignored (reached end-of-life)
Ubuntu 10.04 LTS (Lucid Lynx):needed
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Patches:
Upstream:http://www-01.ibm.com/support/docview.wss?uid=swg24032754
Package
Source: db2 (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2013-04-25 17:14:53 UTC (commit 6757)