IBM Informix I-Spy Local Privilege Escalation Vulnerability
BID:10647
Info
IBM Informix I-Spy Local Privilege Escalation Vulnerability
| Bugtraq ID: | 10647 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 02 2004 12:00AM |
| Updated: | Jul 02 2004 12:00AM |
| Credit: | David Williams reported this vulnerability. |
| Vulnerable: |
IBM Informix I-Spy 2.0 0 |
| Not Vulnerable: | |
Discussion
IBM Informix I-Spy Local Privilege Escalation Vulnerability
It is reported that I-Spy is susceptible to a privilege escalation vulnerability in its 'runbin' binary.
The 'runbin' binary uses its argv[0] to determine both the name of a binary to run, and the path to that binary. 'runbin' is installed setuid root by default.
An attacker with local interactive access to a computer with an affected version of I-Spy installed would be able to exploit this fact to cause attacker specified binaries to be run as the superuser.
I-Spy version 2.x is reported vulnerable to this issue.
It is reported that I-Spy is susceptible to a privilege escalation vulnerability in its 'runbin' binary.
The 'runbin' binary uses its argv[0] to determine both the name of a binary to run, and the path to that binary. 'runbin' is installed setuid root by default.
An attacker with local interactive access to a computer with an affected version of I-Spy installed would be able to exploit this fact to cause attacker specified binaries to be run as the superuser.
I-Spy version 2.x is reported vulnerable to this issue.
Exploit / POC
IBM Informix I-Spy Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
IBM Informix I-Spy Local Privilege Escalation Vulnerability
Solution:
IBM has released a script that will fix the permissions on the appropriate binaries.
IBM Informix I-Spy 2.0 0
Solution:
IBM has released a script that will fix the permissions on the appropriate binaries.
IBM Informix I-Spy 2.0 0
-
IBM I-Spy permissions fix
http://www-1.ibm.com/support/docview.wss?uid=swg21172742&aid=1
References
IBM Informix I-Spy Local Privilege Escalation Vulnerability
References:
References: