Record summary

CVE-2005-4869 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.

Description

The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIBM DB2 DTS To String Conversion - Denial of ServiceExploitDB exploitby Chris AnleyNot analyzed1 file
ExploitDB

PoC details

References

7