Vulnerability Name:

CVE-2007-5757 (CCN-40224)

Assigned:2007-10-31
Published:2008-01-30
Updated:2008-09-05
Summary:Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library.
Note: this might be the same issue as CVE-2008-0697.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.9 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: IBM FTP site
APAR fixes included in Fixpak 16

Source: CONFIRM
Type: UNKNOWN
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT

Source: MITRE
Type: CNA
CVE-2007-5757

Source: IDEFENSE
Type: Patch
20080207 IBM DB2 Universal Database db2pd Arbitrary Library Loading Vulnerability

Source: CCN
Type: SA28771
IBM DB2 UDB Multiple Vulnerabilities

Source: CCN
Type: SECTRACK ID: 1019319
IBM DB2 Alternate Path Bug Lets Local Users Gain Root Privileges

Source: SECTRACK
Type: UNKNOWN
1019319

Source: CCN
Type: IBM APAR IZ03073
SECURITY: DB2PD LOCAL ROOT EXPLOIT VULNERABILITY

Source: CCN
Type: IBM APAR IZ03546
SECURITY: LOCAL ROOT EXPLOITS DB2PD VULNERABILITY

Source: CCN
Type: IBM Technote (FAQ) 1256235
DB2 UDB Version 8 FixPaks and clients

Source: AIXAPAR
Type: UNKNOWN
IZ03546

Source: CCN
Type: IBM Support & downloads
DB2 Version 9.1 fix packs and clients

Source: CCN
Type: IBM Technote (FAQ) 1255572
DB2 Version 9.1 fix packs and clients

Source: CCN
Type: BID-27680
IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerability

Source: CCN
Type: BID-27870
IBM DB2 Universal Database Multiple Vulnerabilities

Source: XF
Type: UNKNOWN
db2-db2pd-privilege-escalation(40224)

Source: CCN
Type: iDefense Labs PUBLIC ADVISORY: 02.07.08
IBM DB2 Universal Database db2pd Arbitrary Library Loading Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:db2_universal_database:*:fixpak_15:*:*:*:*:*:* (Version <= 8.0)
  • OR cpe:/a:ibm:db2_universal_database:9.0:fixpak_3a:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:db2_universal_database:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp15:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:9.1:fp3:aix:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:9.1::fp2:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp1:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp2:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp3:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp4:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp5:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp6:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp8:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp9:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp10:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp11:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp12:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp13:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp14:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:fp7:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm db2 universal database * fixpak_15
    ibm db2 universal database 9.0 fixpak_3a
    ibm db2 universal database 9.1
    ibm db2 universal database 8.2 fp15
    ibm db2 universal database 9.1 fp3
    ibm db2 universal database 9.1
    ibm db2 universal database 8.2
    ibm db2 universal database 8.2 fp1
    ibm db2 universal database 8.2 fp2
    ibm db2 universal database 8.2 fp3
    ibm db2 universal database 8.2 fp4
    ibm db2 universal database 8.2 fp5
    ibm db2 universal database 8.2 fp6
    ibm db2 universal database 8.2 fp8
    ibm db2 universal database 8.2 fp9
    ibm db2 universal database 8.2 fp10
    ibm db2 universal database 8.2 fp11
    ibm db2 universal database 8.2 fp12
    ibm db2 universal database 8.2 fp13
    ibm db2 universal database 8.2 fp14
    ibm db2 universal database 8.2 fp7