CVE-2003-0449 Information
Feb 14, 2021
cve
Description
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries as demonstrated using libjutil.so in_proapsv or (2) the -installdir command line parameter as demonstrated using librocket_r.so in _dbagent.
Reference
http://marc.info/?l=bugtraq&m=105561134624665&w=2 http://marc.info/?l=bugtraq&m=105561189625082&w=2 http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt
Share on: