The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2004-03-16T05:00:00
Updated: 2024-08-08T02:12:36.007Z
Reserved: 2004-03-15T00:00:00
Link: CVE-2003-1033
Vulnrichment
No data.
NVD
Status : Modified
Published: 2004-04-15T04:00:00.000
Modified: 2017-07-11T01:29:40.777
Link: CVE-2003-1033
Redhat
No data.