The Db2 tool db2convert is affected by a buffer overflow vulnerability. As installed this tool does not run with elevated privileges (setuid) and when called directly the vulnerability does not lead to privilege escalation. However, if a customer’s own application or script runs with elevated privileges and executes db2convert, the vulnerability may lead to privilege escalation. This tool is not called by Db2 in such a manner. The vulnerability only exists for local users, it cannot be remotely exploited.
CVE(s): CVE-2018-1515
Affected product(s) and affected version(s):
All fix pack levels of IBM Db2 V10.5 and V11.1 editions on all platforms are affected.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg22016140
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141624
The post IBM Security Bulletin: Buffer overflow in the db2convert tool shipped with IBM® Db2® (CVE-2018-1515). appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2IHbBz6
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.