CVE-2014-3095 Information

Share on:

Description

The SQL engine in IBM DB2 9.5 through FP10 9.7 through FP9a 9.8 through FP5 10.1 through FP4 and 10.5 before FP4 on Linux UNIX and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.

Reference

http://secunia.com/advisories/58725 http://secunia.com/advisories/60845 http://www.securityfocus.com/bid/69546 http://www-01.ibm.com/support/docview.wss?uid=swg1IT02433 http://www-01.ibm.com/support/docview.wss?uid=swg1IT02643 http://www-01.ibm.com/support/docview.wss?uid=swg1IT02644 http://www-01.ibm.com/support/docview.wss?uid=swg1IT02645 http://www-01.ibm.com/support/docview.wss?uid=swg1IT02646 http://www-01.ibm.com/support/docview.wss?uid=swg21681623 http://www-01.ibm.com/support/docview.wss?uid=swg21683297 https://exchange.xforce.ibmcloud.com/vulnerabilities/94263