IBM DB2 'DT_RPATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:48514
Info
IBM DB2 'DT_RPATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 48514 |
| Class: | Design Error |
| CVE: |
CVE-2011-4061 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Tim Brown |
| Vulnerable: |
IBM DB2 9.7 |
| Not Vulnerable: | |
Discussion
IBM DB2 'DT_RPATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
IBM DB2 is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue to gain elevated privileges and execute arbitrary code with root privileges. Successfully exploiting this issue will result in a complete compromise of the affected system.
IBM DB2 9.7 is vulnerable; other versions may also be affected.
IBM DB2 is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue to gain elevated privileges and execute arbitrary code with root privileges. Successfully exploiting this issue will result in a complete compromise of the affected system.
IBM DB2 9.7 is vulnerable; other versions may also be affected.
Exploit / POC
IBM DB2 'DT_RPATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
IBM DB2 'DT_RPATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBM DB2 'DT_RPATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References: