Vulnerability Description
Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 | 9.0 |
Related Weaknesses (CWE)
References
- http://osvdb.org/34024
- http://secunia.com/advisories/24213Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IY94817Vendor Advisory
- http://www.securityfocus.com/bid/22614
- http://www.securitytracker.com/id?1017665
- http://www.securitytracker.com/id?1017695
- http://www.vupen.com/english/advisories/2007/0652
- http://osvdb.org/34024
- http://secunia.com/advisories/24213Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IY94817Vendor Advisory
- http://www.securityfocus.com/bid/22614
- http://www.securitytracker.com/id?1017665
- http://www.securitytracker.com/id?1017695
- http://www.vupen.com/english/advisories/2007/0652
FAQ
What is CVE-2007-1027?
CVE-2007-1027 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
How severe is CVE-2007-1027?
CVE-2007-1027 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1027?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Db2.