Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/518659 | mailing list |
http://www.nth-dimension.org.uk/downloads.php?id=83 | exploit |
http://www.securityfocus.com/bid/51181 | vdb entry |
http://www.securityfocus.com/bid/48514 | vdb entry exploit |
http://www.nth-dimension.org.uk/downloads.php?id=77 | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063 | vdb entry signature |
http://securityreason.com/securityalert/8476 | third party advisory |