>> IBM Informix Dynamic Server Directory Traversal and DoS Vulnerabilities
Title : IBM Informix Dynamic Server Directory Traversal and DoS Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3757 CVE ID : CVE-2007-5956 - CVE-2007-5957
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-07
Technical Description
Two vulnerabilities have been identified in Informix Dynamic Server, which could be exploited by attackers to gain knowledge of sensitive information or cause a denial of service condition.
The first issue is caused by an input validation error within the processing of the DBLANG environment variable, which could be exploited by malicious users to conduct directory traversal attacks.
The second vulnerability is caused by an error when processing "SQ_ONASSIST" requests, which could be exploited by attackers to crash a vulnerable server, creating a denial of service condition.