First published: Tue Oct 03 2006(Updated: )
IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Database Server | =10.uc_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5163 is considered a medium severity vulnerability due to its potential for local exploitation.
To mitigate CVE-2006-5163, you should secure the permissions of the /tmp/installserver.txt file to prevent unauthorized access.
CVE-2006-5163 affects users of IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and potentially other versions.
CVE-2006-5163 is associated with a symlink attack, allowing local users to manipulate file access.
The consequences of CVE-2006-5163 include unauthorized data manipulation and potential system compromise by local users.