Multiple IBM Products Installer Insecure Temporary File Creation Vulnerability
BID:20300
Info
Multiple IBM Products Installer Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 20300 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 02 2006 12:00AM |
| Updated: | Oct 31 2006 09:57PM |
| Credit: | This vulnerability was discovered by Larry Cashdollar <[email protected]>. |
| Vulnerable: |
IBM Informix IDS 10.0 IBM Informix Connect 2.90 IBM Informix Client SDK 2.90 |
| Not Vulnerable: | |
Discussion
Multiple IBM Products Installer Insecure Temporary File Creation Vulnerability
The installation process for multiple IBM products creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully exploiting a symlink attack may allow an attacker to overwrite or corrupt sensitive files. This may result in a denial of service; other attacks may also be possible.
IBM Informix Dynamic Server version 10.0, IBM Informix Client SDK 2.90, and IBM Informix Connect 2.90 are vulnerable to this issue.
The installation process for multiple IBM products creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully exploiting a symlink attack may allow an attacker to overwrite or corrupt sensitive files. This may result in a denial of service; other attacks may also be possible.
IBM Informix Dynamic Server version 10.0, IBM Informix Client SDK 2.90, and IBM Informix Connect 2.90 are vulnerable to this issue.
Exploit / POC
Multiple IBM Products Installer Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
Multiple IBM Products Installer Insecure Temporary File Creation Vulnerability
Solution:
IBM has released an advisory, along with fixes to address this issue. Please see the referenced advisory for more information.
IBM Informix Client SDK 2.90
IBM Informix IDS 10.0
IBM Informix Connect 2.90
Solution:
IBM has released an advisory, along with fixes to address this issue. Please see the referenced advisory for more information.
IBM Informix Client SDK 2.90
IBM Informix IDS 10.0
-
IBM IC50784
http://www-1.ibm.com/support/docview.wss?rs=630&context=SSGU8G&context =SSHPYE&dc=DB550&uid=swg1IC50784&loc=en_US&cs=utf-8&lang=en -
IBM IC50785
http://www-1.ibm.com/support/docview.wss?rs=630&context=SSGU8G&context =SSHPYE&dc=DB550&uid=swg1IC50785&loc=en_US&cs=utf-8&lang=en
IBM Informix Connect 2.90
References
Multiple IBM Products Installer Insecure Temporary File Creation Vulnerability
References:
References: