CVE-2006-4257
published 2006-08-21CVE-2006-4257: IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC…
PriorityP413medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.12%
79.7th percentile
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcpr-x372-mrhj: IBM DB2 Universal Database (UDB) before 8
ghsa_unreviewed·2022-05-03
CVE-2006-4257 [MEDIUM] GHSA-hcpr-x372-mrhj: IBM DB2 Universal Database (UDB) before 8
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
GHSA
GHSA-89gw-fq9p-7x94: IBM DB2 8
ghsa_unreviewed·2022-05-01·CVSS 4.0
CVE-2006-6638 [MEDIUM] GHSA-89gw-fq9p-7x94: IBM DB2 8
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXThttp://secunia.com/advisories/21550http://www-1.ibm.com/support/docview.wss?uid=swg24013114http://www.appsecinc.com/resources/alerts/db2/2006-09-05.shtmlhttp://www.securityfocus.com/archive/1/445298/100/0/threadedhttp://www.securityfocus.com/archive/1/454307/100/0/threadedhttp://www.securityfocus.com/bid/19586http://www.vupen.com/english/advisories/2006/3328ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXThttp://secunia.com/advisories/21550http://www-1.ibm.com/support/docview.wss?uid=swg24013114http://www.appsecinc.com/resources/alerts/db2/2006-09-05.shtmlhttp://www.securityfocus.com/archive/1/445298/100/0/threadedhttp://www.securityfocus.com/archive/1/454307/100/0/threadedhttp://www.securityfocus.com/bid/19586http://www.vupen.com/english/advisories/2006/3328
2006-08-21
Published