CVE-2008-0369
IBM Informix Dynamic Server <10.00.xC8 - Local File Creation
Title source: llmDescription
Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
References (9)
Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/27328
Third Party Advisory third-party-advisory
x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=650
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/28534
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0169
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39751
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1019237
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg27011556
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40009
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IC54309
Scores
EPSS
0.0032
EPSS Percentile
24.3%
Details
Status
published
Products (1)
ibm/informix_dynamic_server
10.00
Published
Jan 19, 2008
Tracked Since
Feb 18, 2026