20050105 IBM DB2 Windows Permission Problems (#NISR05012005F)mailing list
http://marc.info/?l=bugtraq&m=110495402231836&w=2 CVE-2005-4868
HIGH
IBM DB2 - Universal Database Information Disclosure
Record summary
CVE-2005-4868 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIBM DB2 - Universal Database Information DisclosureExploitDB exploitby Chris AnleyNot analyzed1 file
References
712733Third-party advisory
http://secunia.com/advisories/12733 www-1.ibm.comConfirmation
http://www-1.ibm.com/support/docview.wss?uid=swg21181228 nextgenss.com
http://www.nextgenss.com/advisories/db205012005F.txt 11402vdb entry
http://www.securityfocus.com/bid/11402 db2-everyone-gain-access(17605)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17605 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-4868