CVE-2006-5663: Medium severity IBM Informix I-Connect vulnerability
IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5663?
CVE-2006-5663 is typically classified as a medium-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2006-5663?
To fix CVE-2006-5663, adjust the permissions of the installation scripts to limit access for local users.
What products are affected by CVE-2006-5663?
CVE-2006-5663 affects IBM Informix Dynamic Server 10.00, Informix Client SDK 2.90, and Informix I-Connect 2.90.
Can local users exploit CVE-2006-5663?
Yes, local users can exploit CVE-2006-5663 to gain elevated privileges by modifying insecure installation scripts.
Has CVE-2006-5663 been addressed in later versions?
Yes, subsequent versions of the affected IBM Informix products have addressed the issues related to CVE-2006-5663.