Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-02-12 16:00
Updated : 2008-09-05 14:31
NVD link : CVE-2007-5757
Mitre link : CVE-2007-5757
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- db2_universal_database