bk99.de entertain the web since 1997

IBM closes security holes in Informix database

Summary

In August 2006 IBM published updates for several holes in Informix Dynamic Server that NGSSoftware had already reported in January 2005. Functions such as LOTOFILE and SET DEBUG FILE could be used to write arbitrary files, and there were also numerous buffer overflows in SQL functions and at protocol level. One cause of the protocol bugs was the C function getname(), which copies strings unchecked like strcpy().

Ideas

  • Database functions with file access become a way of attacking the operating system.
  • Unchecked copy functions in the style of strcpy() cause buffer overflows.
  • More than a year and a half passed between the report and the patch.

Insights

  • Long vendor response times leave customers unknowingly unprotected.
  • Database servers need hardening like any other network server program.

Facts

  • Affected were, among others, SET DEBUG FILE, IFX_FILE_TO_FILE, FILETOCLOB, LOTOFILE and DBINFO.

References

Critique

  • The report criticises the long response time but names no workarounds for the waiting period.

Recommendations

  • Only allow privileged accounts to use database functions with file access.
  • Do not make database servers reachable from untrusted networks.

Read the original article

Search the Web Archive