PT-2011-4834 · Ibm · Ibm Db2 Express Edition
Tim Brown
·
Published
2011-10-18
·
Updated
2018-10-11
·
CVE-2011-4061
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM DB2 Express Edition 9.7
Description
The issue concerns untrusted search path vulnerabilities in the db2rspgn and kbbacf1 components of IBM DB2 Express Edition. This allows local users to gain privileges by utilizing a Trojan horse libkbb.so in the current working directory, related to the DT RPATH ELF header.
Recommendations
For IBM DB2 Express Edition 9.7, consider restricting access to the db2rspgn and kbbacf1 components to minimize the risk of exploitation. As a temporary workaround, avoid using these components in untrusted environments until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Db2 Express Edition