PT-2019-17087 · Ibm+1 · Ibm Db2 High Performance Unload+1

CVE-2019-4447

·

Publicado

2019-08-26

·

Atualizado

2022-12-02

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DB2 High Performance Unload load for LUW versions 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2
Description The issue concerns a setuid root binary db2hpum debug that trusts the PATH environment variable. A low-privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user-controlled location. When a crash is induced, a trojan gdb command is executed.
Recommendations For IBM DB2 High Performance Unload load for LUW versions 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2, consider restricting the PATH environment variable to prevent it from being altered by low-privileged users. As a temporary workaround, consider disabling the db2hpum debug binary until a patch is available.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-4447

Produtos afetados

Ibm Db2 High Performance Unload
Gdb