Latest versionsfixlist
11.1.0.7 FixList
10.5.0.9 FixList
10.1.0.6 FixList
9.8.0.5 FixList
9.7.0.11 FixList
9.5.0.10 FixList
9.1.0.12 FixList
Have problems? - contact us.
Register for free anmeldung-x26
Contact form kontakt-x26

DB2 - Problem description

Problem IC97470 Status: Closed

SECURITY: NULL POINTER DEREFERENCE IN DB2'S XSLT PARSING ENGINE
(CVE-2013-5466).

product:
DB2 FOR LUW / DB2FORLUW / 970 - DB2
Problem description:
The DB2xslt4 module contains a NULL pointer dereference in the 
XSLT parsing engine which a malicious user could exploit and 
cause the DB2 server to trap and terminate.
Problem Summary:
**************************************************************** 
* USERS AFFECTED:                                              * 
* All DB2 systems on all Linux, Unix and Windows platforms at  * 
* service levels Version 9.7 GA  through to Version 9.7 Fix    * 
* Pack 8                                                       * 
**************************************************************** 
* PROBLEM DESCRIPTION:                                         * 
* See Error Description                                        * 
**************************************************************** 
* RECOMMENDATION:                                              * 
* Upgrade to DB2 Version 9.7 Fix Pack 9.                       * 
****************************************************************
Local Fix:
available fix packs:
DB2 Version 9.7 Fix Pack 9a for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 10 for Linux, UNIX, and Windows

Solution
See Security Bulletin: Denial of Service Vulnerability in DB2's 
XSLT Library. (CVE-2013-5466) 
http://www-01.ibm.com/support/docview.wss?uid=swg21660046
Workaround
not known / see Local fix
Timestamps
Date  - problem reported    :
Date  - problem closed      :
Date  - last modified       :
06.11.2013
16.12.2013
16.12.2013
Problem solved at the following versions (IBM BugInfos)
9.7.FP9
Problem solved according to the fixlist(s) of the following version(s)
9.7.0.9 FixList
9.7.0.9 FixList