CVE-2011-4061
Description
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | db2 | 9.7 | |
| ibm | tivoli_monitoring_for_databases | | |
References
- http://securityreason.com/securityalert/8476
- http://www.nth-dimension.org.uk/downloads.php?id=77
- http://www.nth-dimension.org.uk/downloads.php?id=83
- http://www.securityfocus.com/archive/1/518659
- http://www.securityfocus.com/bid/48514
- http://www.securityfocus.com/bid/51181
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063
- http://securityreason.com/securityalert/8476
- http://www.nth-dimension.org.uk/downloads.php?id=77
- http://www.nth-dimension.org.uk/downloads.php?id=83
- http://www.securityfocus.com/archive/1/518659
- http://www.securityfocus.com/bid/48514
- http://www.securityfocus.com/bid/51181
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14063
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.