IBM Informix Dynamic Server Multiple Vulnerabilities
BID:19264
CVE-2006-3853 | CVE-2006-3855 | CVE-2006-3856 | CVE-2006-3857 | CVE-2006-3858 | CVE-2006-3860 | CVE-2006-3861 | CVE-2006-3862 |Info
IBM Informix Dynamic Server Multiple Vulnerabilities
| Bugtraq ID: | 19264 |
| Class: | Unknown |
| CVE: |
CVE-2006-3853 CVE-2006-3854 CVE-2006-3855 CVE-2006-3857 CVE-2006-3858 CVE-2006-3860 CVE-2006-3862 CVE-2006-3861 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 31 2006 12:00AM |
| Updated: | Aug 15 2006 12:55AM |
| Credit: | David Litchfield and the team at Next Generation Security Software (NGSS) are credited with the discovery of these issues. |
| Vulnerable: |
IBM Informix IDS 9.40 .UC3 IBM Informix IDS 9.40 .UC2 IBM Informix IDS 9.40 .UC1 IBM Informix IDS 9.40.UC5 IBM Informix IDS 9.40.TC5 IBM Informix IDS 9.40 IBM Informix IDS 9.4 IBM Informix IDS 7.31 .xD8 IBM Informix IDS 7.3 IBM Informix IDS 10.0 xC3 IBM Informix IDS 10.0 |
| Not Vulnerable: |
IBM Informix IDS 9.40.xD8 IBM Informix IDS 7.31 .xD9 IBM Informix IDS 10.0.xC4 |
Discussion
IBM Informix Dynamic Server Multiple Vulnerabilities
IBM Informix Dynamic Server is prone to multiple vulnerabilities. These issues can allow attackers to execute arbitrary code and compromise a vulnerable computer, gain elevated privileges, retrieve sensitive information, and trigger denial-of-service conditions.
Some of these issues are remote in nature, while others present a local threat.
IBM Informix Dynamic Server is prone to multiple vulnerabilities. These issues can allow attackers to execute arbitrary code and compromise a vulnerable computer, gain elevated privileges, retrieve sensitive information, and trigger denial-of-service conditions.
Some of these issues are remote in nature, while others present a local threat.
Exploit / POC
IBM Informix Dynamic Server Multiple Vulnerabilities
Several of these issues do not require specific exploit code.
Proof-of-concept exploit code is available from the referenced PDF document called "Informix: Discovery, Attack, and Defense".
Several of these issues do not require specific exploit code.
Proof-of-concept exploit code is available from the referenced PDF document called "Informix: Discovery, Attack, and Defense".
Solution / Fix
IBM Informix Dynamic Server Multiple Vulnerabilities
Solution:
IBM has released IBM Informix Dynamic Server versions 7.31.xD9, 9.40.xD8, 10.00.xC4 to address these issues. Please contact the vendor to obtain fixes.
Solution:
IBM has released IBM Informix Dynamic Server versions 7.31.xD9, 9.40.xD8, 10.00.xC4 to address these issues. Please contact the vendor to obtain fixes.
References
IBM Informix Dynamic Server Multiple Vulnerabilities
References:
References:
- IBM Informix Technical Support (IBM)
- Informix Homepage (IBM)
- Informix: Discovery, Attack, and Defense (David Litchfield)
- SWG1242921 - Security Vulnerabilities Addressed in Informix Dynamic Server (IBM)
- Arbitrary Library Loading in Informix ("NGSSoftware Insight Security Research"
) - Error logging buffer overflow in Informix ("NGSSoftware Insight Security Research"
) - Informix - Discovery, Attack and Defense ("David Litchfield"
) - Informix Long Username Buffer Overflow Vulnerability ("NGSSoftware Insight Security Research"
) - Multiple Arbitrary Command Execution Vulnerabilities ("NGSSoftware Insight Security Research"
) - Multiple Arbitrary File Access (Write/Read) Vulnerabilities ("NGSSoftware Insight Security Research"
) - Multiple Buffer Overflow Vulnerabilities in Informix ("NGSSoftware Insight Security Research"
) - Multiple Password Exposures Flaws ("NGSSoftware Insight Security Research"
) - SQLIDEBUG envariable overflow on Informix ("NGSSoftware Insight Security Research"
) - Unauthorized Database Creation Privilege on Informix ("NGSSoftware Insight Security Research"
)