IBM DB2 Assigns World-Writeable Permissions to Database Managed Space (DMS) Directories
|
|
SecurityTracker Alert ID: 1011060
|
|
SecurityTracker URL: http://securitytracker.com/id?1011060
|
|
CVE Reference: CAN-2003-1049
(Links to External Site)
|
Date: Aug 25 2004
|
Impact: Denial of service via local system, Disclosure of user information, Modification of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 7, 8
|
Description: A vulnerability was reported in IBM's DB2 database. A local user can modify files in the Database Managed Space (DMS) directories.
In December 2003, IBM reported that DB2 creates DMS directories with world-writeable permissions (mode 777). A local user can modify or delete files in those directories.
|
Impact: A local user can modify or delete files in the DMS directories.
|
Solution: A fix is available as part of DB2 Universal Database Version 7 FixPak 12 at:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24007062
The
following Version 8 fixes are available:
Version 8 FixPak 5:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24006465
Version
8 FixPak 4a:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24006358
Version 8 FixPak 6:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24007489
|
Vendor URL: www.ibm.com/support/docview.wss?uid=swg1IY44841 (Links to External Site)
|
Cause: Configuration error
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 23 Dec 2003 02:46:17 -0500
Subject: APAR IY44841 and IY44842
|
> IBM DB2 creates DMS (Database Managed Space) directories with world-writeable
> permissions (mode 777). Malicious local users could take advantage of this issue to
> delete or tamper with files in these directories.
http://www.ibm.com/support/docview.wss?uid=swg1IY44841
IY44841: Security Problem:DMS directory is created with permission 777
A fix is available as part of DB2 Universal Database Version 7 FixPak 12 at:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24007062
http://www.ibm.com/support/docview.wss?uid=swg1IY44842
IY44842: Security Problem:DMS directory is created with permission 777
The following Version 8 fixes are available:
Version 8 FixPak 5:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24006465
Version 8 FixPak 4a:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24006358
Version 8 FixPak 6:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24007489
|
|