IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Informix_dynamic_server | Ibm | 10.uc_rc1 (including) | 10.uc_rc1 (including) |