First published: Fri Dec 31 2004(Updated: )
IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Server | =9.40.uc2 | |
Ibm Informix Extended Parallel Server | =8.40_uc1 | |
IBM Informix Dynamic Server | =9.40.uc1 | |
Ibm Informix Extended Parallel Server | =8.40_uc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2319 is considered a serious vulnerability due to its potential for local file manipulation and unauthorized file reading.
To mitigate CVE-2004-2319, upgrade IBM Informix Dynamic Server to version 9.40.xC3 or later.
CVE-2004-2319 affects IBM Informix Dynamic Server versions before 9.40.xC3 and Extended Parallel Server versions 8.40_uc1 and 8.40_uc2.
CVE-2004-2319 allows local users to create or overwrite files and read arbitrary files through symlink attacks by exploiting log file permissions.
Local users of affected versions of IBM Informix database software are at risk from CVE-2004-2319.