IBM DB2 DB2DIAG.LOG File Local Arbitrary File Overwrite Vulnerability

Solution:
IBM has released an advisory and interim fixes to address this issue. Please see the references for more information.


IBM DB2 Universal Database for AIX 9.0.0 Fixpak 1

IBM DB2 Universal Database for OS/390 and z/OS 8.0 FixPak 13

IBM DB2 Universal Database for Solaris 8.0 FixPak 13

IBM DB2 Universal Database for AIX 8.0 FixPak 13

IBM DB2 Universal Database for Solaris 9.0.0 Fixpak 1

IBM DB2 Universal Database for HP-UX 9.0.0 Fixpak 1

IBM DB2 Universal Database for Linux 8.1 FixPak 14

IBM DB2 Universal Database for OS/390 and z/OS 8.1 FixPak 14

IBM DB2 Universal Database for OS/390 and z/OS 9.0.0 Fixpak 1

IBM DB2 Universal Database for AIX 8.1 FixPak 14

IBM DB2 Universal Database for HP-UX 8.1 FixPak 14

IBM DB2 Universal Database for HP-UX 8.0 FixPak 13

IBM DB2 Universal Database for Linux 9.0.0 Fixpack 1

IBM DB2 Universal Database for Linux 8.0 FixPak 13

IBM DB2 Universal Database for OS/390 and z/OS 6.0

IBM DB2 Universal Database for Solaris 6.0

IBM DB2 Universal Database for AIX 6.0

IBM DB2 Universal Database for AIX 6.1

IBM DB2 Universal Database for Solaris 6.1

IBM DB2 Universal Database for HP-UX 7.0

IBM DB2 Universal Database for AIX 7.0

IBM DB2 Universal Database for Solaris 7.0

IBM DB2 Universal Database for Linux 7.1

IBM DB2 Universal Database for OS/390 and z/OS 7.1

IBM DB2 Universal Database for Solaris 7.1

IBM DB2 Universal Database for AIX 7.1

IBM DB2 Universal Database for HP-UX 7.1

IBM DB2 Universal Database for Solaris 7.2

IBM DB2 Universal Database for Linux 7.2

IBM DB2 Universal Database for AIX 7.2

IBM DB2 Universal Database for HP-UX 7.2

IBM DB2 Universal Database for HP-UX 8.0

IBM DB2 Universal Database for Linux 8.0

IBM DB2 Universal Database for AIX 8.0

IBM DB2 Universal Database for OS/390 and z/OS 8.0

IBM DB2 Universal Database for AIX 8.1

IBM DB2 Universal Database for Solaris 8.1

IBM DB2 Universal Database for Linux 8.1

IBM DB2 Universal Database for HP-UX 8.1

IBM DB2 Universal Database for Solaris 8.1.4

IBM DB2 Universal Database for AIX 8.1.5

IBM DB2 Universal Database for Solaris 8.1.5

IBM DB2 Universal Database for HP-UX 8.1.5

IBM DB2 Universal Database for Linux 8.1.5

IBM DB2 Universal Database for HP-UX 8.1.6

IBM DB2 Universal Database for AIX 8.1.6

IBM DB2 Universal Database for Solaris 8.1.6

IBM DB2 Universal Database for Linux 8.1.6

IBM DB2 Universal Database for HP-UX 8.1.7 b

IBM DB2 Universal Database for AIX 8.1.7

IBM DB2 Universal Database for Solaris 8.1.7

IBM DB2 Universal Database for Solaris 8.1.7 b

IBM DB2 Universal Database for Linux 8.1.7 b

IBM DB2 Universal Database for HP-UX 8.1.7

IBM DB2 Universal Database for HP-UX 8.1.8 a

IBM DB2 Universal Database for Linux 8.1.8 a

IBM DB2 Universal Database for AIX 8.1.8 a

IBM DB2 Universal Database for Solaris 8.1.8 a

IBM DB2 Universal Database for AIX 8.1.8

IBM DB2 Universal Database for Solaris 8.1.8

IBM DB2 Universal Database for HP-UX 8.1.8

IBM DB2 Universal Database for AIX 8.1.9

IBM DB2 Universal Database for HP-UX 8.1.9

IBM DB2 Universal Database for Linux 8.1.9 a

IBM DB2 Universal Database for Solaris 8.1.9

IBM DB2 Universal Database for AIX 8.1.9 a

IBM DB2 Universal Database for Linux 8.1.9

IBM DB2 Universal Database for HP-UX 8.1.9 a

IBM DB2 Universal Database for Linux 8.10

IBM DB2 Universal Database for HP-UX 8.10

IBM DB2 Universal Database for Solaris 8.10

IBM DB2 Universal Database for AIX 8.10

IBM DB2 Universal Database for Linux 8.12

IBM DB2 Universal Database for Linux 8.12

IBM DB2 Universal Database for HP-UX 8.12

IBM DB2 Universal Database for AIX 8.12

IBM DB2 Universal Database for Solaris 8.12

IBM DB2 Universal Database for Linux 8.2

IBM DB2 Universal Database for Linux 9.0

IBM DB2 Universal Database for Solaris 9.0

IBM DB2 Universal Database for OS/390 and z/OS 9.0

IBM DB2 Universal Database for HP-UX 9.0

IBM DB2 Universal Database for AIX 9.0


 

Privacy Statement
Copyright 2010, SecurityFocus