CVE-2009-4334

medium

Description

The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.

References

http://www.vupen.com/english/advisories/2009/3520

http://www.securityfocus.com/bid/37332

http://www-01.ibm.com/support/docview.wss?uid=swg21412902

http://www-01.ibm.com/support/docview.wss?uid=swg21293566

http://www-01.ibm.com/support/docview.wss?uid=swg1IZ50355

http://www-01.ibm.com/support/docview.wss?uid=swg1IZ48106

http://www-01.ibm.com/support/docview.wss?uid=swg1IC64019

http://secunia.com/advisories/37759

Details

Source: Mitre, NVD

Published: 2009-12-16

Updated: 2010-06-29

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium