Vulnerabilities > CVE-2006-5163 - Unspecified vulnerability in IBM Informix Dynamic Server 10.Ucrc1
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
PARTIAL Summary
IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0013.html
- http://secunia.com/advisories/22223
- http://securityreason.com/securityalert/1686
- http://www.osvdb.org/29349
- http://www.securityfocus.com/archive/1/447501/100/0/threaded
- http://www.securityfocus.com/bid/20300
- http://www.vupen.com/english/advisories/2006/3883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29300