IBM Solid Database 6.5 < 184.108.40.206 Multiple Denial of Service Vulnerabilities
Medium Nessus Network Monitor Plugin ID 6340
SynopsisThe remote database server is vulnerable to a denial of service attack.
DescriptionThe remote host is running IBM solidDB.
Versions of solidDB 6.5 earlier than 220.127.116.11 are potentially affected by multiple denial of service vulnerabilities :
- Sending packets with many integer fields can trigger several recursive calls of a certain function causing an excessive amount of stack memory consumption. (CVE-2010-4055, IC80074)
- Upon receiving a packet containing only a single integer field, a NULL pointer dereference can occur causing a daemon crash. (CVE-2010-4056, IC80075)
- When receiving a packet with many different integer fields containing two different values, an invalid memory access and daemon crash can occur. (CVE-2010-4057, IC80076)
SolutionUpgrade to solidDB 18.104.22.168 or later.