Vulnerability Description
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | <= 8.0 |
Related Weaknesses (CWE)
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=654Patch
- http://securitytracker.com/id?1019318
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=654Patch
- http://securitytracker.com/id?1019318
FAQ
What is CVE-2007-3676?
CVE-2007-3676 is a vulnerability with a CVSS score of 10.0 (HIGH). IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co...
How severe is CVE-2007-3676?
CVE-2007-3676 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3676?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2.