iDefense Security Advisory 03.10.08 – Local exploitation of a design error in the “sdbstarter” program, as distributed with SAP AG’s MaxDB, could allow attackers to elevate privileges to root. iDefense has confirmed the existence of this vulnerability in SAP AG’s MaxDB version 7.6.0.37 on both Linux and Solaris. Other versions for Unix-like systems are suspected to be vulnerable. Windows releases do not include the “sdbstarter” program.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/64481/03.10.08-2.txt
Source: https://packetstormsecurity.com/files/64481/iDEFENSE-Security-Advisory-2008-03-10.2.html

