CVE-2006-3859: Medium severity IBM Informix Dynamic Database server vulnerability
IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trltracefileset functions, and the (3) "SET DEBUG FILE" commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3859?
The severity of CVE-2006-3859 is classified as high due to the ability of authenticated users to create and overwrite arbitrary files.
How do I fix CVE-2006-3859?
To fix CVE-2006-3859, ensure that you are using a patched version of IBM Informix Dynamic Server that mitigates the file creation vulnerabilities.
Who is affected by CVE-2006-3859?
CVE-2006-3859 affects users of IBM Informix Dynamic Server versions 9.40.tc4, 9.40.tc7, 9.40.tc8, and 10.00.tc4 and tc5.
Can CVE-2006-3859 be exploited remotely?
Yes, CVE-2006-3859 can be exploited remotely by authenticated users to manipulate file systems.
What are the functions involved in CVE-2006-3859?
The functions involved in CVE-2006-3859 are LOTOFILE, trl_tracefile_set, and the "SET DEBUG FILE" command.