CVE-2002-0905
IBM Informix SE-7.25 - Local Buffer Overflow via INFORMIXDIR Environment Variable
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2002-0905. PoCs published by pHrail, smurf.
AI-analyzed exploit summary This exploit leverages a buffer overflow in the INFORMIXDIR environment variable handled by the setuid root binary `sqlexec` in Informix-SE for Linux. It provides multiple return address options and brute-forcing capabilities to achieve local privilege escalation to root.
Description
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.
Exploits (2)
This exploit leverages a buffer overflow in the INFORMIXDIR environment variable handled by the setuid root binary `sqlexec` in Informix-SE for Linux. It provides multiple return address options and brute-forcing capabilities to achieve local privilege escalation to root.
This exploit leverages a buffer overflow in the INFORMIXDIR environment variable handled by the setuid root executable `sqlexec` in Informix-SE for Linux. It overwrites the return address to execute shellcode, granting root privileges.