← Back

CVE-2012-0711

nvd nist
Published: Mar 20, 2012Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.

Affected (38)

Products: Ibm: Db2
1 product
Db2
Configuration A
38 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 9.1
Version 9.1 fp10
Version 9.1 fp11
Version 9.1 fp1
Version 9.1 fp2
Version 9.1 fp2a
Version 9.1 fp3
Version 9.1 fp3a
Version 9.1 fp4
Version 9.1 fp4a
Version 9.1 fp5
Version 9.1 fp6
Version 9.1 fp6a
Version 9.1 fp7
Version 9.1 fp7a
Version 9.1 fp8
Version 9.1 fp9
Version 9.5
Version 9.5 fp1
Version 9.5 fp2
Version 9.5 fp2a
Version 9.5 fp3
Version 9.5 fp3a
Version 9.5 fp3b
Version 9.5 fp4
Version 9.5 fp4a
Version 9.5 fp5
Version 9.5 fp6
Version 9.5 fp6a
Version 9.5 fp7
Version 9.5 fp8
Version 9.7
Version 9.7 fp1
Version 9.7 fp2
Version 9.7 fp3
Version 9.7 fp3a
Version 9.7 fp4
Version 9.7 fp5
Running on/withPlatform Versions
Ibm
Aix
All versions
Linux
Linux Kernel
All versions
Sun
Sunos
All versions

Related CWEs

Timeline

No history available yet.