vendor:
Progress Database Server
by:
The Itch / BsE
7.5
CVSS
HIGH
Local Root Compromise
Unknown
CWE
Product Name: Progress Database Server
Affected Version From: Progress Database Server v8.3b
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: SCO-Unix and Linux
Unknown
Progress Database Server v8.3b Local Root Compromise
This exploit allows an attacker to gain root access on Progress Database Server v8.3b on Linux and SCO-Unix systems. The exploit was discovered by krfinisterre@checkfree.com and can be used by running the prodbx binary with the appropriate parameters. The exploit contains shellcode for Linux and SCO-Unix systems. The Linux shellcode is a regular shellcode for Linux on the x86 architecture, while the SCO shellcode is specific to SCO-Unix systems.
Mitigation:
Apply vendor patches and updates to address this vulnerability. Regularly update the Progress Database Server to the latest version to ensure that all security patches are applied.