First published: Sat Aug 18 2007(Updated: )
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variable in db2licd (db2licm).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | <=9.1 | |
IBM DB2 Universal Database | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4272 is considered a moderate severity vulnerability due to the potential for local users to exploit it.
To fix CVE-2007-4272, upgrade IBM DB2 UDB to version 8 Fixpak 15 or higher, or version 9.1 Fixpak 3 or higher.
CVE-2007-4272 affects local users of IBM DB2 UDB versions 8.0 before Fixpak 15 and 9.1 before Fixpak 3.
Symptoms of CVE-2007-4272 include unexpected file creation or modification by local users on affected DB2 installations.
CVE-2007-4272 cannot be exploited remotely as it requires local user access to the affected system.