SAP DB RPM Install World Writable Binary Vulnerability
BID:7242
Info
SAP DB RPM Install World Writable Binary Vulnerability
| Bugtraq ID: | 7242 |
| Class: | Design Error |
| CVE: |
CVE-2003-1034 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 31 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery is credited to KF <[email protected]>. |
| Vulnerable: |
SAP DB 7.4 SAP DB 7.3 .00 |
| Not Vulnerable: | |
Discussion
SAP DB RPM Install World Writable Binary Vulnerability
If SA PDB is installed from RPM's, two binaries are left with insecure permissions. The lserver and dbmsrv binaries will both be world writable after performing the RPM installation.
It is important to note that this issue only affects SAPDB installations from RPM's. This issue does not exist when SAPDB is installed from tgz packages.
If SA PDB is installed from RPM's, two binaries are left with insecure permissions. The lserver and dbmsrv binaries will both be world writable after performing the RPM installation.
It is important to note that this issue only affects SAPDB installations from RPM's. This issue does not exist when SAPDB is installed from tgz packages.
Exploit / POC
SAP DB RPM Install World Writable Binary Vulnerability
There is no exploit code necessary.
There is no exploit code necessary.
Solution / Fix
SAP DB RPM Install World Writable Binary Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.