Informix SQL ONSRVAPD Predictable...

- AV AC AU C I A
发布: 2001-09-04
修订: 2025-04-13

Informix is an enterprise database distributed and maintained by IBM. A problem in the onsrvapd program included with the Informix SQL package makes it possible for a local user to overwrite root-owned files, and potentially gain elevated privileges. Upon execution, the onsrvapd program creates a world-writable file in /tmp using the name onsnmp.$HOSTNAME.log, where $HOSTNAME is the name of the system. Since onsrvapd is setuid root, this makes it possible for a local user to overwrite system files, resulting in a denial of service. This could also lead to elevated privileges, including root access.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息