CVE-2019-4016

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155894.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:10.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:10.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

03 Dec 2022, 15:10

Type Values Removed Values Added
CWE CWE-119 CWE-120
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/155894 - VDB Entry, Vendor Advisory (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/155894 - Vendor Advisory, VDB Entry

Information

Published : 2019-03-11 22:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-4016

Mitre link : CVE-2019-4016

CVE.ORG link : CVE-2019-4016


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

ibm

  • db2
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')