CVE-2006-5664: Medium severity IBM Informix Client SDK vulnerability
Published Nov 3, 2006
·Updated
The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.
Affected Software
3 affected components
IBM Informix Client SDK=2.90
IBM Informix Dynamic Server=10.00
IBM Informix I-Connect=2.90
Event History
Nov 3, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:07 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5664?
CVE-2006-5664 has a moderate severity level due to potential local user exploitation via a symlink attack.
2
How do I fix CVE-2006-5664?
To fix CVE-2006-5664, ensure that the installation script does not allow symlink attacks on temporary files.
3
Which software versions are affected by CVE-2006-5664?
CVE-2006-5664 affects IBM Informix Dynamic Server 10.00, Informix Client SDK 2.90, and Informix I-Connect 2.90.
4
Is CVE-2006-5664 exploitable remotely?
CVE-2006-5664 is not remotely exploitable as it requires local user access.
5
What types of attacks does CVE-2006-5664 allow?
CVE-2006-5664 allows local users to compromise security through symlink attacks on temporary files.