Vulnerabilities > CVE-2006-3066 - Unspecified vulnerability in IBM DB2 Universal Database

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
ibm
nessus

Summary

Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.

Nessus

NASL familyDatabases
NASL idDB2_81FP12.NASL
descriptionAccording to its version, the installation of IBM DB2 running on the remote host may crash when it attempts to process a specially crafted CONNECT or ATTACH request sent during the initial handshake process. An unauthenticated, remote attacker can exploit this issue to overflow a buffer and crash the database instance, thereby denying service to legitimate users.
last seen2020-06-01
modified2020-06-02
plugin id23935
published2006-12-23
reporterThis script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/23935
titleIBM DB2 < 8.1 FixPak 12 EXCSAT Long MGRLVLLS Message Remote DoS