Get a Pentest and security assessment of your IT network.

Advisories

NISR02082006C.txt

NGSSoftware Insight Security Research Advisory – Informix Dynamic Server is a database developed by IBM. An attacker can force to the database server to load an arbitrary library and thus execute arbitrary code. The ifx_load_internal SQL function can be used to load an arbitrary library into the address space of the database server process. By placing code in the DllMain() function on Windows or _init() on Linux an attacker can have this code execute automatically when the library is loaded. In conjunction with exploiting other flaws it is possible to remotely create a library over SQL, dump this to the server disk and then load it. All versions are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/49295/NISR02082006C.txt

Source: https://packetstormsecurity.com/files/49295/NISR02082006C.txt.html

Related posts
Advisories

57657.html

Advisories

Secunia Security Advisory 17317

Advisories

Ubuntu Security Notice 284-1

Advisories

Zero Day Initiative Advisory 06-040