PT-2003-1634 · Progress · Progress Database

Kf

·

Publicado

2003-06-20

·

Atualizado

2016-10-18

·

CVE-2003-0449

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Progress Database versions 9.1 to 9.1D06
Description: The issue allows local users to gain privileges by exploiting the trust in user input to find and load libraries using dlopen(). This can be achieved through manipulating the PATH environment variable to point to malicious libraries, such as libjutil.so in proapsv, or by utilizing the -installdir command line parameter with malicious libraries like librocket r.so in dbagent.
Recommendations: For Progress Database versions 9.1 to 9.1D06, consider restricting access to the dlopen() function or limiting the ability to modify the PATH environment variable and the -installdir command line parameter to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0449

Produtos afetados

Progress Database