Update Protection against IBM DB2 Database Server CONNECT Request Denial of Service Vulnerability
| Check Point Reference: | CPAI-2009-094 | |
| Date Published: | ||
| Preemptive Since: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA33529 | |
| Industry Reference(s): | CVE-2009-0172 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? IBM DB2 prior to 9.1 FP6a IBM DB2 prior to 9.5 FP3a | ||
| Vulnerability Description A denial of service vulnerability has been reported in IBM DB2 Database Server. IBM DB2 Database is a relational database management system that consists of a set of services that work together to provide data processing functionalities. A remote attacker may exploit this issue to cause the vulnerable server to stop responding. |
||
|
Update/Patch Available Apply patches: IBM |
|
|
Vulnerability Details The vulnerability is due to insufficient input validation by the IBM DB2 Database Server while processing malformed connect data streams. A remote attacker may exploit this issue by sending a malicious Distributed Relational Database Architecture (DRDA) connect data stream to the server. Successful exploitation of this vulnerability will cause the server to enter an infinite loop once it will process the malformed CONNECT request, creating a denial of service condition. |
Protection Overview
This protection will detect and block malformed CONNECT requests sent to the IBM DB2 Database Server.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, Protection tab and select the version of your choice
To configure the defense, select your product from the list below and follow the related protection steps.