CVE-2008-0369

IBM Informix Dynamic Server <10.00.xC8 - Local File Creation

Title source: llm
STIX 2.1

Description

Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27328
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=650
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28534
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0169
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39751
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019237
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27011556
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40009
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IC54309

Scores

EPSS 0.0032
EPSS Percentile 24.3%

Details

Status published
Products (1)
ibm/informix_dynamic_server 10.00
Published Jan 19, 2008
Tracked Since Feb 18, 2026