Wednesday, May 23, 2018

IBM Security Bulletin: Multiple vulnerabilities affect db2exmig and db2exfmt tools shipped with IBM® Db2® (CVE-2018-1544, CVE-2018-1565)

The Db2 tools db2exmig and db2exfmt are affected by a buffer overflow vulnerability. As installed these tools do not run with elevated privileges (setuid) and when called directly the vulnerability does not lead to privilege escalation. However, if a customer’s own application or script runs with elevated privileges and executes db2exmig or db2exfmt, the vulnerability may lead to privilege escalation. These tools are not called by Db2 in such a manner. The vulnerability only exists for local users, it cannot be remotely exploited.

CVE(s): CVE-2018-1544, CVE-2018-1565

Affected product(s) and affected version(s):

All fix pack levels of IBM Db2 V9.7, V10.1, V10.5, and V11.1 editions on all platforms are affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg22016143
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/142648
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/143022

The post IBM Security Bulletin: Multiple vulnerabilities affect db2exmig and db2exfmt tools shipped with IBM® Db2® (CVE-2018-1544, CVE-2018-1565) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2LrnUkT

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.