Lucene search

K
exploitdbSNOSoftEDB-ID:23345
HistoryNov 07, 2003 - 12:00 a.m.

IBM DB2 - 'db2stop' Format String Arbitrary Code Execution

2003-11-0700:00:00
SNOSoft
www.exploit-db.com
20

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/8989/info
 
Multiple command-line parameter format string vulnerabilities have been discovered in various IBM DB2 binaries. Specifically, format-based functions are implemented erroneously within the db2govd, db2start, and db2stop programs. These binaries are typically installed setuid. As a result, a malicious local user may be capable of gaining elevate privileges.

[kf@RiotStarter adm]$ ./db2stop %n%n
Segmentation fault

AI Score

7.4

Confidence

Low

Related for EDB-ID:23345