IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability
BID:27680
Info
IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27680 |
| Class: | Design Error |
| CVE: |
CVE-2007-5757 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2008 12:00AM |
| Updated: | Feb 08 2008 01:06AM |
| Credit: | The discoverer of this vulnerability wishes to remain anonymous. |
| Vulnerable: |
IBM DB2 Universal Database for Linux 9.1 FixPack 2 |
| Not Vulnerable: |
IBM DB2 Universal Database for Linux 9.1 FixPak 4 IBM DB2 Universal Database for Linux 8.2.0 Fixpak 16 |
Discussion
IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability
IBM DB2 Universal Database Server is prone to a local privilege-escalation vulnerability because of how the application contructs library paths.
Exploiting this issue allows local attackers to gain root privileges. Note that an attacker must be able to execute the set-uid root 'db2pd' binary to exploit this issue.
DB2 Universal Database Server 9.1 FixPack 2 on Linux systems is vulnerable. Other versions, including those for other UNIX platforms, are suspected to be vulnerable.
NOTE: This vulnerability was previously disclosed in BID 27596 'IBM DB2 Universal Database Server 8.2 Prior To Fixpak 16 Multiple Local Vulnerabilities'. Due to more information, it has been assigned its own record.
IBM DB2 Universal Database Server is prone to a local privilege-escalation vulnerability because of how the application contructs library paths.
Exploiting this issue allows local attackers to gain root privileges. Note that an attacker must be able to execute the set-uid root 'db2pd' binary to exploit this issue.
DB2 Universal Database Server 9.1 FixPack 2 on Linux systems is vulnerable. Other versions, including those for other UNIX platforms, are suspected to be vulnerable.
NOTE: This vulnerability was previously disclosed in BID 27596 'IBM DB2 Universal Database Server 8.2 Prior To Fixpak 16 Multiple Local Vulnerabilities'. Due to more information, it has been assigned its own record.
Exploit / POC
IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability
An attacker can exploit this issue by gaining local interactive access to the affected computer. Note that the attacker must be able to execute the set-uid root 'db2pd' binary to exploit this issue.
An attacker can exploit this issue by gaining local interactive access to the affected computer. Note that the attacker must be able to execute the set-uid root 'db2pd' binary to exploit this issue.
Solution / Fix
IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
References
IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability
References:
References:
- 02.07.08 IBM DB2 Universal Database db2pd Arbitrary Library Loading Vulnerabilit (iDefense Labs)
- DB2 UDB Version 8 FixPaks and clients (IBM)
- DB2 Version 9.1 fix packs and clients (IBM)
- IBM DB2 Homepage (IBM)
- iDefense Security Advisory 02.07.08: IBM DB2 Universal Database db2pdArbitrary (iDefense Labs
)