First published: Fri Nov 03 2006(Updated: )
IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Informix I-connect | =2.90 | |
IBM Informix Dynamic Server | =10.00 | |
IBM Informix Client SDK | =2.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5663 is typically classified as a medium-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2006-5663, adjust the permissions of the installation scripts to limit access for local users.
CVE-2006-5663 affects IBM Informix Dynamic Server 10.00, Informix Client SDK 2.90, and Informix I-Connect 2.90.
Yes, local users can exploit CVE-2006-5663 to gain elevated privileges by modifying insecure installation scripts.
Yes, subsequent versions of the affected IBM Informix products have addressed the issues related to CVE-2006-5663.