Security Bulletin
Summary
InstallShield/installAnywhere generates installation executables which are vulnerable to a DLL-planting affecting the installation of IBM Informix CSDK and Dynamic Server on Windows.
Vulnerability Details
CVEID: CVE-2016-2542
DESCRIPTION: Flexera InstallShield could allow a local attacker to gain elevated privileges on the system, caused by an untrusted search path. An attacker could exploit this vulnerability using a Trojan horse DLL in the current working directory of a setup-launcher executable file to gain elevated privileges on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110914 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2016-4560
DESCRIPTION: Flexera InstallAnywhere could allow a local attacker to gain elevated privileges on the system, caused by an untrusted search path. An attacker could exploit this vulnerability using a Trojan horse DLL in the current working directory of a setup-launcher executable file to gain elevated privileges on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/113016 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Products and Versions
IBM Informix CSDK 3.50, 3.70, 4.10 for Windows
IBM Informix Dynamic Server 11.50, 11.70, 12.10 for Windows
Remediation/Fixes
VRMF | Remediation/First Fix | |
Informix CSDK | 3.50, 3.70
4.10 | Use workaround or call Support.
Fixed in 4.10.xC7. |
Informix Server | 11.50, 11.70
12.10 | Use workaround or call Support.
Fixed in 12.10.xC7. |
Workarounds and Mitigations
Informix CSDK 3.50 and Informix Server 11.50 use InstallShield. For these products use the following steps for installation:
- As an administrator, create a new secure folder. Only the administrator should have write permission to the new folder.
- Unzip the files from your installation media into this new folder.
- Rename the file setup.exe to ids_install.exe or clientsdk_install.exe. Do not skip this step.
- Run ids_install.exe or clientsdk_install.exe from this directory to install the product. Proceed with the installation as normal.
Informix CSDK 3.70, 4.10 and Informix Server 11.70, 12.10 use InstallAnywhere. For these products use the following steps for installation:
- As an administrator, create a new secure folder. Only the administrator should have write permission to the new folder.
- Unzip the files from your installation media into this new folder.
- Run ids_install.exe or clientsdk_install.exe from this directory to install the product. Proceed with the installation as normal.
Note that this vulnerability is only at installation time and the currently running versions are not affected.
Get Notified about Future Security Bulletins
References
Change History
8 June 2016: Original version published
30 June 2016: Updated for 12.10.xC7
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
16 June 2018
UID
swg21984231