IBM Support

Security Bulletin: Vulnerability in InstallShield/InstallAnywhere affects IBM Informix CSDK and Server installation on Windows(CVE-2016-2542, CVE-2016-4560)

Security Bulletin


Summary

InstallShield/installAnywhere generates installation executables which are vulnerable to a DLL-planting affecting the installation of IBM Informix CSDK and Dynamic Server on Windows.

Vulnerability Details

CVEID: CVE-2016-2542
DESCRIPTION: Flexera InstallShield could allow a local attacker to gain elevated privileges on the system, caused by an untrusted search path. An attacker could exploit this vulnerability using a Trojan horse DLL in the current working directory of a setup-launcher executable file to gain elevated privileges on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110914 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2016-4560
DESCRIPTION: Flexera InstallAnywhere could allow a local attacker to gain elevated privileges on the system, caused by an untrusted search path. An attacker could exploit this vulnerability using a Trojan horse DLL in the current working directory of a setup-launcher executable file to gain elevated privileges on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/113016 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM Informix CSDK 3.50, 3.70, 4.10 for Windows

IBM Informix Dynamic Server 11.50, 11.70, 12.10 for Windows

Remediation/Fixes


VRMFRemediation/First Fix
Informix CSDK3.50, 3.70

4.10

Use workaround or call Support.

Fixed in 4.10.xC7.

Informix Server11.50, 11.70

12.10

Use workaround or call Support.

Fixed in 12.10.xC7.

Workarounds and Mitigations

Informix CSDK 3.50 and Informix Server 11.50 use InstallShield. For these products use the following steps for installation:

  1. As an administrator, create a new secure folder. Only the administrator should have write permission to the new folder.
  2. Unzip the files from your installation media into this new folder.
  3. Rename the file setup.exe to ids_install.exe or clientsdk_install.exe. Do not skip this step.
  4. Run ids_install.exe or clientsdk_install.exe from this directory to install the product. Proceed with the installation as normal.

Informix CSDK 3.70, 4.10 and Informix Server 11.70, 12.10 use InstallAnywhere. For these products use the following steps for installation:
  1. As an administrator, create a new secure folder. Only the administrator should have write permission to the new folder.
  2. Unzip the files from your installation media into this new folder.
  3. Run ids_install.exe or clientsdk_install.exe from this directory to install the product. Proceed with the installation as normal.

Note that this vulnerability is only at installation time and the currently running versions are not affected.

Get Notified about Future Security Bulletins

References

Off

Change History

8 June 2016: Original version published
30 June 2016: Updated for 12.10.xC7

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSGU8G","label":"Informix Servers"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF022","label":"OS X"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"11.5;11.7;12.1","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
16 June 2018

UID

swg21984231