Interbase GDS_Lock_MGR UMask File Permission Changing Vulnerability
BID:5805
Info
Interbase GDS_Lock_MGR UMask File Permission Changing Vulnerability
| Bugtraq ID: | 5805 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1514 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Borland/Inprise Interbase 6.5 Borland/Inprise Interbase 6.0 Borland/Inprise Interbase 5.0 Borland/Inprise Interbase 4.0 |
| Not Vulnerable: | |
Discussion
Interbase GDS_Lock_MGR UMask File Permission Changing Vulnerability
Interbase is a SQL database distributed and maintained by Borland. It is available for Unix and Linux operating systems.
The gds_lock_mgr program within Interbase is typically installed setuid. This program does not properly handle user-supplied umasks, and may allow the creation of files with insecure permissions as a privileged user.
Interbase is a SQL database distributed and maintained by Borland. It is available for Unix and Linux operating systems.
The gds_lock_mgr program within Interbase is typically installed setuid. This program does not properly handle user-supplied umasks, and may allow the creation of files with insecure permissions as a privileged user.
Exploit / POC
Interbase GDS_Lock_MGR UMask File Permission Changing Vulnerability
Exploit contributed by <[email protected]>:
Exploit contributed by <[email protected]>:
Solution / Fix
Interbase GDS_Lock_MGR UMask File Permission Changing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Interbase GDS_Lock_MGR UMask File Permission Changing Vulnerability
References:
References:
- Interbase Homepage (Borland/Inprise)