CVE-2003-0449: Medium severity Progress Database vulnerability

Published Jun 20, 2003
·
Updated

Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so inproapsv, or (2) the -installdir command line parameter, as demonstrated using librocketr.so in dbagent.

Affected Software

1 affected component
Progress Database=9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Before starting in_proapsv, ensure the PATH environment variable does not contain directories writable by non-privileged users and contains only trusted system directories so dlopen cannot load malicious libraries (mitigates loading of libjutil.so).

    in_proapsv PATH environment variable = exclude untrusted or user-writable directories; include only trusted system directories (e.g., /usr/bin:/bin:/usr/local/bin)
  2. Configuration

    Launch _dbagent only with a trusted absolute path for -installdir (or omit the parameter) and validate that the path is not user-writable so dlopen cannot load malicious libraries (mitigates loading of librocket_r.so).

    _dbagent -installdir command-line parameter = specify a trusted absolute path or do not use a user-controlled path
  3. Compensating control

    Restrict ability to modify or execute Progress Database binaries (in_proapsv, _dbagent) and to alter their environment (including PATH) via filesystem permissions, host-level ACLs, or local user restrictions so unprivileged users cannot influence library loading.

  4. Operational

    Search systems for the files libjutil.so and librocket_r.so in directories that may appear in PATH or be supplied via -installdir; if unexpected copies are found, quarantine or remove them and investigate for evidence of local privilege escalation.

Event History

Jun 20, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 7, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2003-0449?

CVE-2003-0449 has a moderate severity rating due to its potential for privilege escalation.

2

How do I fix CVE-2003-0449?

To fix CVE-2003-0449, ensure that environment variables and command line parameters aren't exploited to load malicious libraries.

3

Who is affected by CVE-2003-0449?

CVE-2003-0449 affects users of Progress Database versions 9.1 to 9.1D06.

4

What types of vulnerabilities are exploited in CVE-2003-0449?

CVE-2003-0449 exploits trust in user input to load libraries via the dlopen function.

5

Can CVE-2003-0449 be exploited remotely?

CVE-2003-0449 is a local vulnerability that requires local user access to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203