Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:38
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT - | |
References | () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=653 - Patch | |
References | () http://securitytracker.com/id?1019319 - | |
References | () http://www-1.ibm.com/support/docview.wss?uid=swg1IZ03546 - |
Information
Published : 2008-02-13 00:00
Updated : 2024-11-21 00:38
NVD link : CVE-2007-5757
Mitre link : CVE-2007-5757
CVE.ORG link : CVE-2007-5757
JSON object : View
Products Affected
ibm
- db2_universal_database
CWE
CWE-264
Permissions, Privileges, and Access Controls