CVE-2005-4869
IBM DB2 8.1 - Denial of Service via to_char and to_date Empty String Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4869. PoCs published by Chris Anley.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in IBM DB2 by triggering a trap during DTS to string conversion when an empty formatting string is provided to the 'to_char' or 'to_date' functions.
Description
The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
Exploits (1)
This exploit demonstrates a denial-of-service vulnerability in IBM DB2 by triggering a trap during DTS to string conversion when an empty formatting string is provided to the 'to_char' or 'to_date' functions.