CVE-2017-1297

IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:data_server_client:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:data_server_driver_for_odbc_and_cli:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:data_server_driver_package:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:data_server_runtime_client:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*
cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_workgroup:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:express:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:workgroup:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_workgroup:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:express:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:workgroup:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:advanced_enterprise:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:advanced_workgroup:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:express:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:workgroup:*:*:*
cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:application_server:*:*:*
cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:unlimited:*:*:*
cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:application_server:*:*:*
cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:unlimited:*:*:*
cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:application_server:*:*:*
cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:unlimited:*:*:*
cpe:2.3:a:ibm:db2_connect:11.1.0.0:*:*:*:application_server:*:*:*
cpe:2.3:a:ibm:db2_connect:11.1.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:ibm:db2_connect:11.1.0.0:*:*:*:unlimited:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-06-27 16:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-1297

Mitre link : CVE-2017-1297

CVE.ORG link : CVE-2017-1297


JSON object : View

Products Affected

ibm

  • db2
  • data_server_client
  • data_server_driver_package
  • db2_connect
  • data_server_driver_for_odbc_and_cli
  • data_server_runtime_client

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer