First published: Fri Jan 18 2008(Updated: )
Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Server | =10.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0369 has a low to medium severity rating due to its potential for local users to create arbitrary files.
To mitigate CVE-2008-0369, upgrade IBM Informix Dynamic Server to version 10.00.xC8 or later.
Local users of IBM Informix Dynamic Server versions prior to 10.00.xC8 are affected by CVE-2008-0369.
CVE-2008-0369 is a local file creation vulnerability that can be exploited by local users.
CVE-2008-0369 specifically impacts IBM Informix Dynamic Server version 10.00.