A remotely exploitable buffer overflow exists in IBM DB2. This issue is due to insufficient bounds checking of library names passed to the stored procedure interface. Successful exploitation may allow execution of arbitrary code, compromising the database server. This is likely one of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.
A remotely exploitable buffer overflow exists in IBM DB2. This issue is due to insufficient bounds checking of library names passed to the stored procedure interface. Successful exploitation may allow execution of arbitrary code, compromising the database server. This is likely one of the issues announced in BIDs 11089 and 11327. It is now being assigned its own BID since the vendor has provided additional technical information.