First published: Thu May 08 2003(Updated: )
Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP MaxDB | =7.3.29 | |
SAP MaxDB | =7.4.3.7_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0265 is classified as a critical vulnerability due to its potential to allow local attackers to gain root privileges.
To fix CVE-2003-0265, update SAP Database to a version that does not have this vulnerability, preferably above version 7.4.3.7.
CVE-2003-0265 affects SAP database versions 7.3.29 and 7.4.3.7_beta.
No, CVE-2003-0265 can only be exploited locally due to the nature of the vulnerability.
Exploiting CVE-2003-0265 allows a local attacker to modify critical files and potentially gain root privileges on the system.