Wednesday, May 23, 2018

IBM Security Bulletin: Buffer overflow in the db2convert tool shipped with IBM® Db2® (CVE-2018-1515).

The Db2 tool db2convert is affected by a buffer overflow vulnerability. As installed this tool does not run with elevated privileges (setuid) and when called directly the vulnerability does not lead to privilege escalation. However, if a customer’s own application or script runs with elevated privileges and executes db2convert, the vulnerability may lead to privilege escalation. This tool is not called by Db2 in such a manner. The vulnerability only exists for local users, it cannot be remotely exploited.

CVE(s): CVE-2018-1515

Affected product(s) and affected version(s):

All fix pack levels of IBM Db2 V10.5 and V11.1 editions on all platforms are affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg22016140
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141624

The post IBM Security Bulletin: Buffer overflow in the db2convert tool shipped with IBM® Db2® (CVE-2018-1515). appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2IHbBz6

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.