Informix Dynamic Server Uses Unsafe Installation Scripts and Directory Permissions That May Let Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1017156 |
|
SecurityTracker URL: http://securitytracker.com/id/1017156
|
|
CVE Reference:
CVE-2006-5663, CVE-2006-5664
(Links to External Site)
|
Date: Nov 3 2006
|
Impact:
User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 10.0
|
Description:
Two vulnerabilities were reported in Informix. A local user can obtain elevated privileges on the target system.
The installation scripts are installed with insecure permissions [CVE-2006-5663]. A local user can modify the scripts to gain elevated privileges.
The installation process creates temporary files in the /tmp directory in an unsafe manner [CVE-2006-5664]. A local user can create a symbolic link (symlink) from a critical file on the target system to one of the temporary files. Then, when the installation scripts are run by a target user, the symlinked file may be created or overwritten with the privileges of the target user.
The Informix Dynamic Server, Informix Client Software Development Kit (CSDK), and Informix I-Connect components are affected.
|
Impact:
A local user can obtain elevated privileges on the target system.
|
Solution:
The vendor has issued the following APARs:
IBM Informix Dynamic Server installserver script: IC50785
IBM Informix Dynamic Server (Bundle) ids_install script: IC50784
IBM Informix CSDK installclientsdk script: IC50783
IBM Informix Connect installconn script: IC50786
The vendor plans to issue the following fixed versions.
IBM Informix Dynamic Server for Solaris Opteron, Linux zSeries:
10.00.xC5R1
IBM Informix Dynamic Server for all others:
10.00.xC6
IBM Informix CSDK for Solaris Opteron, Linux zSeries:
2.90.xC4R1
IBM Informix CSDK for all others:
2.90.xC7
IBM Informix Connect for Solaris Opteron, Linux zSeries:
2.90.xC4R1
IBM Informix Connect for all others:
2.90.xC7
The IBM advisory is available at:
http://www-1.ibm.com/support/docview.wss?uid=swg21247438
|
Vendor URL: www-1.ibm.com/support/docview.wss?uid=swg21247438 (Links to External Site)
|
Cause:
Access control error, State error
|
Underlying OS:
Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (SGI/IRIX), UNIX (Solaris - SunOS)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 3 Nov 2006 11:40:07 -0500
Subject: Possible security vulnerabilities with Informix Dynamic Server, CSDK, and I-Connect product installers
|
http://www-1.ibm.com/support/docview.wss?uid=swg21247438
CVE-2006-5663
CVE-2006-5664
|
|