HIGH
Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library
Published May 30, 2014
7.2
HIGHCVSS 2.0
EPSS 0.66%
Description
Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
Affected products
No data.
OR
- 9.5
- 9.7
- 9.7.0.1
- 9.7.0.2
- 9.7.0.3
- 9.7.0.4
- 9.7.0.5
- 9.7.0.6
- 9.7.0.7
- 9.7.0.8
- 9.7.0.9
- 10.1
- 10.1.0.1
- 10.1.0.2
- 10.1.0.3
- 10.5
- 10.5.0.1
- 10.5.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (22)
- http://packetstormsecurity.com/files/126940/IBM-DB2-Privilege-Escalation.html x_refsource_MISC
- http://seclists.org/fulldisclosure/2014/Jun/7 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/59451 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59463 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60482 third-party-advisoryx_refsource_SECUNIA
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT00627 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT00684 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT00685 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT00686 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT00687 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=swg21680454 x_refsource_CONFIRM
- http://www-304.ibm.com/support/docview.wss?uid=swg21676135 x_refsource_CONFIRM
- http://www.ibm.com/support/docview.wss?uid=swg1IT00686 x_refsource_CONFIRM
- http://www.ibm.com/support/docview.wss?uid=swg21610582#4 x_refsource_CONFIRMVendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21672100 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/67617 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1030670 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id/1030671 vdb-entryx_refsource_SECTRACK
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91869 vdb-entryx_refsource_XF
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-0907/ x_refsource_MISC
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published May 30, 2014
Updated Aug 6, 2024
Reserved Jan 6, 2014
Link CVE-2014-0907
CISA Vulnrichment
Updated n/a