Informix SQL Temporary Log File Symbolic Link Vulnerability
BID:3281
Info
Informix SQL Temporary Log File Symbolic Link Vulnerability
| Bugtraq ID: | 3281 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 04 2001 12:00AM |
| Updated: | Sep 04 2001 12:00AM |
| Credit: | This issue was announced by <[email protected]> via Bugtraq on September 4, 2001. |
| Vulnerable: |
IBM Informix SQL 7.31 .UC5 |
| Not Vulnerable: | |
Discussion
Informix SQL Temporary Log File Symbolic Link Vulnerability
Informix is an enterprise database software package designed for use on multiple platforms. It is distributed and maintained by IBM.
The programs onbar_d, ondblog, and onsmsync create predictable files in the /tmp directory. Upon execution of any one of the three programs, files bar_dbug.log and bar_act.log are created in /tmp with root and informix read-write permissions.
As these programs are setuid root, and setgid informix, it may be possible to overwrite root-owned files, resulting in a denial of service, and potentially an elevation of privileges.
Informix is an enterprise database software package designed for use on multiple platforms. It is distributed and maintained by IBM.
The programs onbar_d, ondblog, and onsmsync create predictable files in the /tmp directory. Upon execution of any one of the three programs, files bar_dbug.log and bar_act.log are created in /tmp with root and informix read-write permissions.
As these programs are setuid root, and setgid informix, it may be possible to overwrite root-owned files, resulting in a denial of service, and potentially an elevation of privileges.
Exploit / POC
Informix SQL Temporary Log File Symbolic Link Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Informix SQL Temporary Log File Symbolic Link Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Informix SQL Temporary Log File Symbolic Link Vulnerability
References:
References: