Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IBM DB2 Shared Library Injection Vulnerability

IBM DB2 ships with a number of shared libraries, stored in a directory owned by the user and group 'bin'. As setuid root utilities are linked to these libraries, their ownership by a user and group of a lower privilege level constitutes a vulnerability. If an attacker can obtain user or group bin privileges, the shared libraries can be overwritten with malicious replacements designed to obtain root privileges from the setuid root utilities that use them.







 

Privacy Statement
Copyright 2008, SecurityFocus