Vulnerabilities > CVE-2010-4057 - Numeric Errors vulnerability in IBM Soliddb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | IBM solidDB. CVE-2010-4055,CVE-2010-4056,CVE-2010-4057. Dos exploits for multiple platform |
file | exploits/multiple/dos/15261.txt |
id | EDB-ID:15261 |
last seen | 2016-02-01 |
modified | 2010-10-15 |
platform | multiple |
port | |
published | 2010-10-15 |
reporter | Luigi Auriemma |
source | https://www.exploit-db.com/download/15261/ |
title | IBM solidDB <= 6.5.0.3 - Denial of Service Vulnerability |
type | dos |
Nessus
NASL family | Databases |
NASL id | SOLIDDB_6_5_0_8.NASL |
description | The remote database system is affected by multiple denial of service vulnerabilities : - Sending packets with many integer fields can trigger several recursive calls of a certain function causing an excessive amount of stack memory consumption. (CVE-2010-4055, IC80074) - Upon receiving a packet containing only a single integer field, a NULL pointer dereference can occur causing a daemon crash. (CVE-2010-4056, IC80075) - When receiving a packet with many different integer fields containing two different values, an invalid memory access and daemon crash can occur. (CVE-2010-4057, IC80076) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 58105 |
published | 2012-02-23 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/58105 |
title | IBM solidDB 6.5 < 6.5.0.8 Multiple Denial of Service Vulnerabilities |
code |
|
References
- http://aluigi.altervista.org/adv/soliddb_1-adv.txt
- http://aluigi.altervista.org/adv/soliddb_1-adv.txt
- http://secunia.com/advisories/41873
- http://secunia.com/advisories/41873
- http://securitytracker.com/id?1024597
- http://securitytracker.com/id?1024597
- http://www.exploit-db.com/exploits/15261
- http://www.exploit-db.com/exploits/15261
- http://www.vupen.com/english/advisories/2010/2715
- http://www.vupen.com/english/advisories/2010/2715
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62590
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62590