Borland Interbase Database User Privilege Escalation Vulnerability
BID:9929
Info
Borland Interbase Database User Privilege Escalation Vulnerability
| Bugtraq ID: | 9929 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 20 2004 12:00AM |
| Updated: | Mar 20 2004 12:00AM |
| Credit: | Discovered by Larry Cashdollar <http://vapid.dhs.org>. |
| Vulnerable: |
Borland/Inprise Interbase 7.1 Borland/Inprise Interbase 7.0 Borland/Inprise Interbase 6.5 Borland/Inprise Interbase 6.4 Borland/Inprise Interbase 6.0 Borland/Inprise Interbase 5.0 Borland/Inprise Interbase 4.0 |
| Not Vulnerable: | |
Discussion
Borland Interbase Database User Privilege Escalation Vulnerability
By default, insecure permissions are set on the file storing the user database that is shipped with Borland Interbase. The permissions, 0666, permit all users to write to the file. This configuration error can be exploited to gain administrative access within the database. The consequences of this flaw may extend further if the database supports applications.
By default, insecure permissions are set on the file storing the user database that is shipped with Borland Interbase. The permissions, 0666, permit all users to write to the file. This configuration error can be exploited to gain administrative access within the database. The consequences of this flaw may extend further if the database supports applications.
Exploit / POC
Borland Interbase Database User Privilege Escalation Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Borland Interbase Database User Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Borland Interbase Database User Privilege Escalation Vulnerability
References:
References:
- iDEFENSE Security Advisory 03.19.04: Borland Interbase admin.ib Administrative A (iDEFENSE)
- InterBase Security Best Practices - by Borland Developer Support Staff (Borland Software Corporation)