Progress Database Environment...

- AV AC AU C I A
发布: 2003-06-14
修订: 2025-04-13

It has been reported that Progress database does not properly handle untrusted input when opening shared libraries. Specifically, the dlopen() function used by several Progress utilities checks the user's PATH environment variable when including shared object libraries. If any shared objects are found, Progress will load and execute them. Due to this, an attacker may be able to gain unauthorized privileges. Any library code loaded will execute with elevated privileges.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息