2.1
CVSSv2

CVE-2005-4869

Published: 31/12/2005 Updated: 29/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm db2 8.1

Exploits

source: wwwsecurityfocuscom/bid/11400/info IBM DB2 is reported prone to a denial of service vulnerability when DTS to string conversion is carried out It is reported that during a DTS to string conversion a trap occurs if an empty formatting string is provided The vulnerability is exposed in the 'to_char' and 'to_date' conversion funct ...