CVE-2003-1052: High severity IBM DB2 vulnerability
Published Aug 20, 2004
·Updated
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
Affected Software
8 affected components
IBM DB2=9.0
IBM DB2 Universal Database=6.0
IBM DB2 Universal Database=7.0
IBM DB2 Universal Database=7.1
IBM DB2 Universal Database=7.2
IBM DB2 Universal Database=8.0
IBM DB2 Universal Database=8.1
IBM DB2 Universal Database=8.2
Remediation
Patch Available
Patch Available
Event History
Aug 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1052?
CVE-2003-1052 is considered a critical vulnerability due to the potential for root privilege escalation.
2
How do I fix CVE-2003-1052?
To fix CVE-2003-1052, update IBM DB2 to the latest patched version to mitigate the vulnerability.
3
What versions of IBM DB2 are affected by CVE-2003-1052?
IBM DB2 versions 6.0, 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 are all affected by CVE-2003-1052.
4
What impact does CVE-2003-1052 have on systems?
CVE-2003-1052 allows an unauthorized user to gain root privileges, which can lead to complete system compromise.
5
Is there a workaround for CVE-2003-1052?
A potential workaround for CVE-2003-1052 includes restricting access to the bin user or removing setuid permissions from root programs.