CVE-2008-3958
IBM DB2 UDB < 8.0 - Denial of Service via Crafted CONNECT/ATTACH Data Stream
Title source: llmDescription
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
References (6)
Core 6
Core References
Various Sources x_refsource_confirm
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31058
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ08134
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/31787
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/48144
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45133
Scores
EPSS
0.0161
EPSS Percentile
73.4%
Details
Status
published
Products (2)
ibm/db2
8.0 (22 CPE variants)
ibm/db2
< 8.0
Published
Sep 11, 2008
Tracked Since
Feb 18, 2026