Re: DB2UDB hack

Edwin Davidson <EDavidson-FhXUXP1Pus5Wk0Htik3J/[email protected]> Thu, 25 Oct 2007 10:05:32 -0500
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
While I can't answer this specific vulnerability, every time that I have 
perused similar cross platform overflows, under runs and such the 
conclusion ended up being that the AS/400 wasn't vulnerable because the 
OS doesn't allow for over flows and under runs resulting in code 
execution.  I've pursued  these in BIND and HTTP/Apache 
vulnerabilities.   I wouldn't be surprised if that was also the case 
with the database.







**********************************************************************
This email and any files transmitted with it are confidential
and intended solely for the use of the individual or entity to
whom they are addressed.  If you have received this email
in error please reply to the sender of the message.

The views expressed in this correspondence may not
reflect the views of Prime, Inc.

This footnote also confirms that this email message has
been scanned for the presence of computer viruses.
http://www.primeinc.com
**********************************************************************

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.