[VIM] CVE Dupes: 2007-4418 and 2005-2073 and CVE-2007-1089

security curmudgeon jericho at attrition.org
Wed Apr 30 20:23:17 UTC 2008


Oh, I should clarify:

: APAR:
: http://www-1.ibm.com/support/docview.wss?uid=swg1IY73104

Fixes:

DB2 Universal Database Version 8 FixPak 9a (also known as Version 8.2 FixPak 2a)
DB2 UDB Version 8.1 FixPak 10 (also known as Version 8.2 FixPak 3)
DB2 UDB Version 8.1 FixPak 11 (also known as Version 8.2 FixPak 4)
DB2 UDB Version 8.1 FixPak 12 (also known as Version 8.2 FixPak 5)
DB2 UDB Version 8.1 FixPak 13 (also known as Version 8.2 FixPak 6)
DB2 UDB Version 8.1 FixPak 14 (also known as Version 8.2 FixPak 7)
DB2 Universal Database Version 8 FixPak 8a (also known as Version 8.2 FixPak 1a)
DB2 UDB Version 8.1 FixPak 15 (also known as Version 8.2 FixPak 8)
DB2 UDB Version 8.1 FixPak 16 (also known as Version 8.2 FixPak 9)

: APAR:
: http://www-1.ibm.com/support/docview.wss?uid=swg1JR25940

DB2 UDB Version 8.1 FixPak 15 (also known as Version 8.2 FixPak 8)
DB2 UDB Version 8.1 FixPak 16 (also known as Version 8.2 FixPak 9)

: No changelog but this APAR:
: http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941

DB2 Version 9.1 Fix Pack 2 for Linux, UNIX and Windows
DB2 Version 9.1 Fix Pack 3 for Linux, UNIX and Windows
DB2 Version 9.1 Interim Fix Pack 3a for Linux, UNIX and Windows
DB2 Version 9.1 Fix Pack 4 for Linux, UNIX and Windows
DB2 Version 9.1 Fix Pack 4a for Linux, UNIX and Windows


So we definitely have different versions affected, mainly between the 8 
and 9 branches. That is why we have APAR 2594[0|1] and they are linked. 
But it doesn't explain 73104 and no links to the other APARs, especially 
25940.



More information about the VIM mailing list