Re: Aaaaaaaaaaaooooooogah - security alert
Posted in 2006
No. But if might be solved with IDS 10.00xC5. You don't want to use
any 10 fixpack lower than 10.00xC4X4 which contains the secuity fixes
and fixes for other known issues with prior releases of IDS 10.
Christine Normile
christinenormile@mac.com
On Oct 4, 2006, at 9:39 AM, Ford, Andrew G wrote:
> http://secunia.com/advisories/22223/
>
> Description:
> Larry Cashdollar has discovered a vulnerability in IBM Informix
> Dynamic Server, which can be exploited by malicious, local users to
> perform certain actions with escalated privileges.
>
> The vulnerability is caused due to the temporary file "/tmp/
> installserver.txt" being created insecurely during the install
> process. This can be exploited via symlink attacks to append data
> to arbitrary files with privileges of the user running the
> installation script.
>
> The vulnerability has been confirmed in version 10.UC3RC1 Trial for
> Linux. Other versions may also be affected.
>
> Solution:
> Grant only trusted user access to affected systems.>
>
>
>
>
> Can this be solved by setting DBTEMP to a secure directory?
>
> Andrew Ford
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list