Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-5757
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5757

Description:
Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.

CVE Status:
Candidate

References:

ST
  1019319

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=653

CONFIRM

AIXAPAR
  http://www-1.ibm.com/support/docview.wss?uid=swg1IZ03546


Return to the previous page.