CVE-2007-5757

Properties

Published:
11.02.2008
Updated:
14.02.2008
Patch available:
Severity:
Medium
CVSS vector:
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Product:
IBM: DB2 Universal Database
IBM: DB2 Universal Database

Vulnerability description

Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library.  NOTE: this might be the same issue as CVE-2008-0697.

References:

IDEFENSE: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=653
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT: ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT
SECTRACK: http://securitytracker.com/id?1019319