HIGH · 7.5

CVE-2012-0711

Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to e...

Vulnerability Description

Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmDb29.1
IbmAixAll versions
LinuxLinux KernelAll versions
SunSunosAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0711?

CVE-2012-0711 is a vulnerability with a CVSS score of 7.5 (HIGH). Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to e...

How severe is CVE-2012-0711?

CVE-2012-0711 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0711?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2, Ibm Aix, Linux Linux Kernel, Sun Sunos.