Vulnerability Name:
CVE-2006-6638 (CCN-28614)
Assigned:
2006-08-18
Published:
2006-08-18
Updated:
2008-09-05
Summary:
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than
CVE-2006-4257
.
CVSS v3 Severity:
3.5 Low
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
Required
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Low
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
)
3.7 Low
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
4.0 Medium
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P
)
3.0 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Denial of Service
References:
Source: CCN
Type: Full-Disclosure Mailing List, Wed Dec 13 2006 - 13:29:42 CST
IBM DB2 Remote DoS during CONNECT processing
Source: MITRE
Type: CNA
CVE-2006-4257
Source: MITRE
Type: CNA
CVE-2006-6638
Source: CCN
Type: SA21550
DB2 Universal Database Denial of Service Vulnerabilities
Source: CCN
Type: SA23397
DB2 Universal Database Denial of Service Vulnerability
Source: SECUNIA
Type: Patch, Vendor Advisory
23397
Source: CCN
Type: IBM APAR IY86917
SECURITY: Remote denial of service during CONNECT / ATTACH processing
Source: CCN
Type: IBM APAR IY87211
SECURITY: Remote denial of service after CONNECT processing
Source: AIXAPAR
Type: Patch
IY91847
Source: CCN
Type: IBM APAR IY94370
SECURITY: USING THE DWB DEBUG TOOLS TO A VERSION 8 SERVER WILL CRASH THE SERVER.
Source: CCN
Type: IBM Support & downloads
DB2 UDB Version 8.1 FixPak 13 (also known as Version 8.2 FixPak 6)
Source: MISC
Type: Patch, Vendor Advisory
http://www.appsecinc.com/resources/alerts/db2/2006-11-30.shtml
Source: CCN
Type: OSVDB ID: 27993
IBM DB2 Universal Database CONNECT Processing Unspecified DoS
Source: CCN
Type: OSVDB ID: 34022
IBM DB2 DB2ENGN.DLL Crafted SQLJRA Packet Remote DoS
Source: CCN
Type: BID-19586
IBM DB2 Multiple Denial of Service Vulnerabilities
Source: BID
Type: Patch
21646
Source: CCN
Type: BID-21646
IBM DB2 Remote SQLJRA Packet Denial of Service Vulnerability
Source: XF
Type: UNKNOWN
db2-connect-attach-dos(28614)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:ibm:db2_universal_database:8.1:*:aix:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.6c:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.7b:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.8:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.8a:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.9:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.9a:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.10:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.12:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:ibm:db2_universal_database:8.1.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.6c:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.7b:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.8:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.8a:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.9:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.1.9a:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.10:*:*:*:*:*:*:*
OR
cpe:/a:ibm:db2_universal_database:8.2:*:*:*:*:*:*:*
AND
cpe:/o:sun:solaris:::x86:*:*:*:*:*
OR
cpe:/o:ibm:aix:4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:aix_5l:-:*:*:*:*:*:*:*
OR
cpe:/o:sun:solaris:10.0::sparc:*:*:*:*:*
Denotes that component is vulnerable
BACK
ibm
db2 universal database 8.1
ibm
db2 universal database 8.1.4
ibm
db2 universal database 8.1.5
ibm
db2 universal database 8.1.6
ibm
db2 universal database 8.1.6c
ibm
db2 universal database 8.1.7
ibm
db2 universal database 8.1.7b
ibm
db2 universal database 8.1.8
ibm
db2 universal database 8.1.8a
ibm
db2 universal database 8.1.9
ibm
db2 universal database 8.1.9a
ibm
db2 universal database 8.10
ibm
db2 universal database 8.12
ibm
db2 universal database 8.1.4
ibm
db2 universal database 8.1.5
ibm
db2 universal database 8.1.6
ibm
db2 universal database 8.1.6c
ibm
db2 universal database 8.1.7
ibm
db2 universal database 8.1.7b
ibm
db2 universal database 8.1.8
ibm
db2 universal database 8.1.8a
ibm
db2 universal database 8.1.9
ibm
db2 universal database 8.1.9a
ibm
db2 universal database 8.10
ibm
db2 universal database 8.2
sun
solaris
ibm
aix 4
ibm
aix 5l -
sun
solaris 10.0