33529Third-party advisory
http://secunia.com/advisories/33529 CVE-2009-0172
IBM DB2 < 9.5 pack 3a - Connect Denial of Service
Record summary
CVE-2009-0172 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIBM DB2 < 9.5 pack 3a - Connect Denial of ServiceExploitDB exploitby Dennis YurichevNot analyzed1 file
References
101021591vdb entry
http://securitytracker.com/id?1021591 IZ37696Vendor advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ37696 www-01.ibm.comConfirmation
http://www-01.ibm.com/support/docview.wss?uid=swg21363936 IZ36534Vendor advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ36534 IZ37697Vendor advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ37697 33258vdb entry
http://www.securityfocus.com/bid/33258 ADV-2009-0137vdb entry
http://www.vupen.com/english/advisories/2009/0137 ibm-db2-connect-stream-dos(47931)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/47931 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0172