PT-2006-5901 · Ibm · Ibm Informix Dynamic Server

Larry W. Cashdollar

·

Publicado

2006-10-03

·

Atualizado

2018-10-17

·

CVE-2006-5163

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Informix Dynamic Server version 10.UC3RC1 Trial for Linux
Description The issue allows local users to append data to arbitrary files via a symlink attack, due to insecure permissions of the /tmp/installserver.txt file created by the software.
Recommendations For IBM Informix Dynamic Server version 10.UC3RC1 Trial for Linux, consider changing the permissions of the /tmp/installserver.txt file to prevent local users from appending data to arbitrary files via a symlink attack. As a temporary workaround, restrict access to the /tmp directory to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5163

Produtos afetados

Ibm Informix Dynamic Server