First published: Wed Apr 16 2008(Updated: )
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DB2 Universal Database | =9.5 | |
IBM DB2 Universal Database | =8 | |
IBM DB2 Universal Database | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5664 has a medium severity rating due to its potential for local file overwriting through symlink attacks.
To fix CVE-2007-5664, apply the appropriate Fix Pack updates for your version of IBM DB2 Universal Database.
CVE-2007-5664 affects local users of IBM DB2 Universal Database versions 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16.
CVE-2007-5664 demonstrates a symlink attack that allows local users to overwrite arbitrary files.
Systems running IBM DB2 Universal Database versions 8.0, 9.1, and 9.5 prior to their respective fixes are vulnerable to CVE-2007-5664.