CVE-2009-4325

critical

Description

The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."

References

http://www.vupen.com/english/advisories/2009/3520

http://www.securityfocus.com/bid/37332

http://www-01.ibm.com/support/docview.wss?uid=swg21412902

http://www-01.ibm.com/support/docview.wss?uid=swg21293566

http://www-01.ibm.com/support/docview.wss?uid=swg1LI74504

http://www-01.ibm.com/support/docview.wss?uid=swg1IC64702

http://secunia.com/advisories/37759

Details

Source: Mitre, NVD

Published: 2009-12-16

Updated: 2010-06-29

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Severity: Critical