Web Programming Talk

Please login or register.

Login with username, password and session length
Advanced search  

News:

Free Web Hosting Package for You! Click here for more infomation.

Author Topic: IBM DB2 Universal Database Local Privilege Escalation Vulnerabilities  (Read 1310 times)

sphere

  • Guest

Multiple vulnerabilities have been identified in IBM DB2 Universal Database, which could be exploited by local attackers to gain elevated privileges.

The first issue is caused by an error in the "db2dasrrm" utility that creates the "dasRecoveryIndex", "dasRecoveryIndex.tmp", ".dasRecoveryIndex.lock", and "dasRecoveryIndex.cor" with insecure permissions, which could be exploited by the "dasusr1" user or a local attacker (member of the "db2adm1" group) to gain root privileges via symbolic links.

The second vulnerability is caused by a buffer overflow error in the "db2dasrrm" utility when processing the "DASPROF" environment variable, which could be exploited by local attackers to execute arbitrary code with root privileges.
  
Logged

Shole

  • Full Member
  • ***
  • Reputation: 0
  • Posts: 115
    • View Profile
    • IHost4You
Re: IBM DB2 Universal Database Local Privilege Escalation Vulnerabilities
« Reply #1 on: December 04, 2010, 12:15:25 AM »

Good guide :) where do you find all of them or do you write them yourself?
Logged
Ihost4you.com
 

anything