CVE-2007-1027: Medium severity IBM DB2 vulnerability
Published Feb 21, 2007
·Updated
Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
Affected Software
2 affected components
IBM DB2=9.0
IBM DB2=9.0
Event History
Feb 21, 2007
CVE Published
11:28 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1027?
CVE-2007-1027 has a medium severity rating due to the potential for unauthorized local file overwriting.
2
How do I fix CVE-2007-1027?
To fix CVE-2007-1027, upgrade to IBM DB2 Fix Pack 2 or later versions.
3
What systems are affected by CVE-2007-1027?
CVE-2007-1027 affects IBM DB2 version 9.0 running on Linux and Unix systems.
4
Is CVE-2007-1027 a remote code execution vulnerability?
No, CVE-2007-1027 is not a remote code execution vulnerability; it allows local users to exploit the flaw.
5
Can CVE-2007-1027 be exploited without authentication?
Yes, CVE-2007-1027 can be exploited by any local user with access to the system.