Security Notice for CA Products That Embed Ingres

1897

28 February 2021

24 May 2019

OPEN

 

Issued: August 1, 2008

CA Support is alerting customers to multiple security risks in CA products that embed Ingres. Multiple vulnerabilities exist that can allow a remote attacker to execute arbitrary code, gain privileges, or cause a denial of service condition. These vulnerabilities exist in the products and on the platforms listed below. These vulnerabilities do not impact any Windows-based Ingres installation.

The first vulnerability, CVE-2008-3356, allows an unauthenticated attacker to potentially set the user and/or group ownership of a verifydb log file to be Ingres allowing read/write permissions to both.

The second vulnerability, CVE-2008-3357, allows an unauthenticated attacker to exploit a pointer overwrite vulnerability to execute arbitrary code within the context of the database server process.

The third vulnerability, CVE-2008-3389, allows an unauthenticated attacker to obtain ingres user privileges. However, when combined with the unsecured directory privileges vulnerability (CVE–2008-3357), root privileges can be obtained.

Risk Rating

High

Affected Platforms

  1. Ingres verifydb file create permission override (CVE-2008-3356)
    This vulnerability impacts all platforms except Windows.

  2. Ingres un-secure directory privileges with utility ingvalidpw (CVE - 2008-3357)
    This vulnerability impacts only Linux and HP platforms.

  3. Ingres verifydb, iimerge, csreport buffer overflow (CVE-2008-3389)
    This vulnerability impacts only Linux and HP platforms.

Affected Products

Admin r8.1 SP2
Advantage Data Transformer r2.2
Allfusion Harvest Change Manager r7.1
CA ARCserve Backup for Unix r11.1, r11.5 GA/SP1/SP2/SP3
CA ARCserve Backup for Linux r11.1, r11.5 GA/SP1/SP2/SP3
CA Directory r8.1
CA Job Management Option R11.0
CA Single Sign-On r8.1
CleverPath Aion BPM r10.1, r10.2
EEM (eIAM) 8.1, 8.2, 8.2.1, 8.3
eTrust Audit/SCC 8.0 sp2
Identity Manager r12
NSM 3.0 0305, 3.1 0403, r3.1 SP1 0703, r11
Unicenter Asset Management r11.1, r11.2
Unicenter Remote Control r11.2
Unicenter Service Catalog r2.2, r11.1
Unicenter Service Metric Analysis r11.1
Unicenter ServicePlus Service Desk 6.0, r11, r11.1, r11.2
Unicenter Software Delivery r11.1, r11.2
Unicenter Workload Control Center r11

How to determine if the installation is affected

For these products:

Admin r8.1 SP2
ARCserve for Linux r11.5 SP2/SP3
CA Directory r8.1
CA Job Management Option R11.0
CA Single Sign-On r8.1
EEM 8.2
EEM 8.2.1
EEM 8.3
eTrust Audit/SCC 8.0 sp2
Identity Manager r12
NSM r11
Unicenter Asset Management r11.1
Unicenter Asset Management r11.2
Unicenter Remote Control r11.2
Unicenter Service Catalog r11.1
Unicenter Service Metric Analysis r11.1
Unicenter ServicePlus Service Desk r11
Unicenter ServicePlus Service Desk r11.1
Unicenter ServicePlus Service Desk r11.2
Unicenter Software Delivery r11.1
Unicenter Software Delivery r11.2
Unicenter Workload Control Center r11

The Ingres release information is maintained in %II_SYSTEM%ingresversion.rel:

UNIX or Linux: cat version.rel

The release identifier will be as follows:

Operating System Release identifier
HP Sparc 32/64bit II 3.0.3 (hp2.us5/211)
HP Itanium II 3.0.3 (i64.hpu/211)
Intel Solaris 32/64bit II 3.0.3 (a64.sol/211)
AIX 32/64bit II 3.0.3 (r64.us5/211)
Solaris 32/64bit II 3.0.3 (su9.us5/211)
AMD Linux II 3.0.3 (a64.lnx/211)
Intel Linux II 3.0.3 (int.lnx/103)
Itanium Linux II 3.0.3 (i64.lnx/211)

Notes:

  1. You would need to install the Ingres build instead of the patch if either of the following is true:

    1. If the Ingres release for your platform is not 3.0.3 in the release identifier

      or

    2. The Ingres release is 3.0.3 but the build level is not 103 for Linux and 211 for all the Unix platforms.

    3. If either of the above is true then download and apply the latest build for your operating system(s).

    4. If the OS platform you are running Ingres on is not listed, please contact Technical Support.

    For these products:

    Advantage Data Transformer r2.2
    Allfusion Harvest Change Manager r7.1
    ARCserve for Linux r11.5 GA/SP1
    CleverPath Aion BPM r10.1
    CleverPath Aion BPM r10.2

    The maintenance updates are provided for the latest r3 builds supported by CA which are 3.0.3/103 (Linux) and 3.03/211 (UNIX platforms). If the build embedded is earlier than 3.0.3, it has to be upgraded to 3.0.3 to fix the vulnerabilities.

    The Ingres release information is maintained in %II_SYSTEM%ingresversion.rel:

    UNIX or Linux: cat version.rel

    The release identifier will be as follows:

    Operating System Release identifier
    HP Sparc 32/64bit II 3.0.3 (hp2.us5/211)
    HP Itanium II 3.0.3 (i64.hpu/211)
    Intel Solaris 32/64bit II 3.0.3 (a64.sol/211)
    AIX 32/64bit II 3.0.3 (r64.us5/211)
    Solaris 32/64bit II 3.0.3 (su9.us5/211)
    AMD Linux II 3.0.3 (a64.lnx/211)
    Intel Linux II 3.0.3 (int.lnx/103)
    Itanium Linux II 3.0.3 (i64.lnx/211)

    Important:

    For Linux (AMD, Intel and Itanium) platforms, after applying the build provided on this page, please download and apply the maintenance update. For the other platforms, the builds are patched to the latest maintenance update.

    Note:

    1. If the release you are using is already 3.0.3 build 103 on Linux and 3.0.3 build 211 on Unix, then download and install the maintenance update.

    2. If the OS platform you are running Ingres on is not listed, please contact Technical Support.

    For these products:

    CA ARCserve Backup for Unix r11.1
    CA ARCserve Backup for Unix r11.5 GA/SP1/SP2
    CA ARCserve Backup for Unix r11.5 SP3
    CA ARCserve Backup for Linux r11.1
    EEM (eIAM) 8.1
    NSM 3.0 0305
    NSM 3.1 0403
    NSM r3.1 SP1 0703
    Unicenter Service Catalog r2.2
    Unicenter ServicePlus Service Desk 6.0

    The Ingres release information is maintained in %II_SYSTEM%ingresversion.rel:

    UNIX or Linux: cat version.rel

    The release identifier will be as follows:

    Operating System Release identifier
    AIX 32bit II 2.6/xxxx (rs4.us5/00)
    AIX 64bit II 2.6/xxxx (r64.us5/00)
    HP-UX Itanium II 2.6/xxxx (i64.hpu/00)
    HP-UX RISC 32bit II 2.6/xxxx (hpb.us5/00)
    HP-UX RISC 32bit II 2.6/xxxx (hpb.us5/00)DBL
    HP-UX RISC 64bit II 2.6/xxxx (hp2.us5/00)
    HP Tru64 UNIX II 2.6/xxxx (axp.osf/00)
    Linux AMD64 II 2.6/xxxx (a64.lnx/00)
    Linux Intel 32bit II 2.6/xxxx (int.lnx/00)
    Linux Intel 32bit II 2.6/xxxx (int.lnx/00)DBL
    Linux Intel 32bit II 2.6/xxxx (int.lnx/00)LFS
    Linux Itanium II 2.6/xxxx (i64.lnx/00)
    Linux S/390 II 2.6/xxxx (ibm.lnx/00)
    Solaris SPARC 32bit II 2.6/xxxx (su4.us5/00)
    Solaris SPARC 32bit double II 2.6/xxxx (su4.us5/00)DBL
    Solaris SPARC 64bit II 2.6/xxxx (su9.us5/00)

    Note:

    1. If the OS platform you are running Ingres on is not listed, please contact Technical Support.

    2. For HP-UX platform with CA ARCserve Backup 11.1 or 11.5/GA/SP1/SP2/SP3, download the published ARCserve fix, RO01277, and follow the enclosed instructions to install the security patch.

    Solution

    The most prudent course of action for affected customers is to download and apply the corrective maintenance. However, updates are provided only for the following releases: 2.6 and r3

    Important: Customers using products that embed an earlier version of Ingres r3 should upgrade Ingres to the release that is currently supported (3.0.3/103 on Linux and 3.0.3/211 on UNIX platforms) before applying the maintenance updates. Please contact your product's Technical Support team for more information.

    For these products:

    Admin r8.1 SP2
    CA ARCserve Backup for Linux r11.5 SP2/SP3
    CA Directory r8.1
    CA Job Management Option R11.0
    CA Single Sign-On r8.1
    EEM 8.2
    EEM 8.2.1
    EEM 8.3
    eTrust Audit/SCC 8.0 sp2
    Identity Manager r12
    NSM r11
    Unicenter Asset Management r11.1
    Unicenter Asset Management r11.2
    Unicenter Remote Control r11.2
    Unicenter Service Catalog r11.1
    Unicenter Service Metric Analysis r11.1
    Unicenter ServicePlus Service Desk r11
    Unicenter ServicePlus Service Desk r11.1
    Unicenter ServicePlus Service Desk r11.2
    Unicenter Software Delivery r11.1
    Unicenter Software Delivery r11.2
    Unicenter Workload Control Center r11

    Apply the update below that is listed for your platform:

    AIX [3.0.3 (r64.us5/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12833-r64-us5.tar.z

    HP-UX Itanium [3.0.3 (i64.hpu/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12831-i64-hpu.tar.z

    HP-UX RISC [3.0.3 (hp2.us5/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12830-hp2-us5.tar.z

    Linux AMD [3.0.3 (a64.lnx/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12835-a64-lnx.tar.z

    Linux Intel 32bit [3.0.3 (int.lnx/103)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.103.12836-int-lnx.tar.z

    Linux Itanium [3.0.3 (i64.lnx/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12838-i64-lnx.tar.z

    Solaris SPARC [3.0.3 (su9.us5/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12834-su9-us5.tar.z

    Solaris x64/x86 [3.0.3 (a64.sol/211)]
    https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/patch-3.0.3.211.12832-a64-sol.tar.z

    Ingres r3 Vulnerability Updates Install Steps (August 1, 2008)

    Unix/Linux:

    1. Log on to your system using the installation owner account and make sure the environment is set up correctly:

      1. II_SYSTEM must be set to the Ingres system files

      2. PATH must include $II_SYSTEM/bin and $II_SYSTEM/utility directories.

      3. Change directory to the root directory of the Ingres installation or use a previously created directory.


        cd $II_SYSTEM/ingres


        or


        cd <patch_directory>

      4. Copy the download maintenance update file in to the current directory and uncompress

      5. Read in the update file with the following commands:


        umask 022


        tar xf [update_file]


        This will create the directory:


        $II_SYSTEM/ingres/patchXXXXX


        or


        <patch_directory>/patchXXXXX

        Note: ‘XXXXX' in patchXXXXX refers to the update number

      6. Stop all Ingres processes with the ‘ingstop' utility:


        ingstop

      7. Change directory to the patch directory:


        cd patchXXXXX

      8. Within the patch directory run the following command:


        ./utility/iiinstaller

        Please check the $II_SYSTEM/ingres/files/patch.log file to make sure the patch was applied successfully. Also check the $II_SYSTEM/ingres/version.rel to make sure the patch is referenced.

        Note: The patch can also be installed silently using the ‘-m' flag with iiinstaller:
        ./utility/iiinstaller -m

      9. Once the patch install has been complete, re-link the iimerge binary with the following command:


        iilink

      10. Ingres can then be restarted with the ‘ingstart' utility:


        ingstart

      For these products:

      Advantage Data Transformer r2.2
      Allfusion Harvest Change Manager r7.1
      ARCserve for Linux r11.5 GA/SP1
      CleverPath Aion BPM r10.1
      CleverPath Aion BPM r10.2

      Apply the build below that is listed for your platform:

      AIX
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/install-3.0.3.211.12833-r64-us5.tar

      HP-UX Itanium
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/install-3.0.3.211.12831-i64-hpu.tar

      HP-UX RISC
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/install-3.0.3.211.12830-hp2-us5.tar

      Linux AMD EI build
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/ingres-3.0.3-211-EI-linux-x86_64.tar.gz

      Linux AMD II build
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/ingres-3.0.3-211-linux-x86_64.tgz

      Linux Intel EI build
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/ingres-3.0.3-103-EI-linux-i386.tgz

      Linux Intel II build
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/ingres-3.0.3-103-pc-linux-i386.tgz

      Linux Itanium EI build
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/ingres-3.0.3-211-EI-linux-ia64.tar.gz

      Linux Itanium II build
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/ingres-3.0.3-211-linux-ia64.tgz

      Solaris SPARC
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/install-3.0.3.211.12834-su9-us5.tar

      Solaris x64/x86
      https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/r3/install-3.0.3.211.12832-a64-sol.tar

      Ingres r3 Build Install Steps (August 1, 2008)

      Important: Prior to installing the build, a full operating system backup of the $II_SYSTEM/ingres directory on Unix/Linux and %II_SYSTEM%ingres directory on Windows must be taken with Ingres completely shut down. Also, a backup of any other DATA locations that you may have must be taken, again with Ingres shut down. In case there is a problem with the update install, this allows Ingres to be restored from the backup.

      Unix:

      1. Log in to the system as the installation owner and make sure the environment is set up correctly:

        1. II_SYSTEM must be set to the Ingres home directory

        2. PATH must include $II_SYSTEM/ingres/bin and $II_SYSTEM/ingres/utility directories

        3. Add $II_SYSTEM/ingres/lib to the shared library path

        4. Set TERM to ‘vt100' and TERM_INGRES to ‘vt100fx'

        5. Copy the downloaded update file to the /tmp directory and uncompress

        6. Read in the update file with the following commands:


          umask 022

          tar xf [update_file]


          This creates a directory containing the distribution and other files.

        7. Stop all applications that may be connected to or using any of the files in the Ingres instance.

        8. Stop all Ingres processes with the ‘ingstop' utility:


          ingstop

        9. Important: Take an operating system backup of the $II_SYSTEM/ingres directory and other DATA locations that you may have elsewhere. Also, copy the $II_SYSTEM/ingres/files/config.dat and $II_SYSTEM/ingres/files/symbol.tbl files to a safe location to ensure that the configuration can be restored.

        10. From the root directory of the Ingres installation ($II_SYSTEM/ingres), run the following command:
          tar xf /tmp/<update_directory>/ingres.tar install

        11. Run the following command:


          install/ingbuild

        12. The initial install screen appears.

        13. In the Distribution medium enter the full path to the ‘ingres.tar' file (including the file) (See step 4).

        14. Choose PackageInstall from the list of installation options and then choose ‘Stand alone DBMS Server' from the list of packages. Then choose ExpressInstall.

        15. Choose Yes in the pop-up screen and press Enter key.

          The install utility verifies that each component was transferred properly from the distribution medium. When this is finished (without errors), another pop-up screen for setting up the components comes up.

        16. Select Yes and press Enter key to go to the Setup program.

        17. Once the installation is complete, check the $II_SYSTEM/ingres/files/install.log for any errors. Also, check the $II_SYSTEM/ingres/version.rel file to verify the new build is referenced; this should show 3.0.3 for the build.

        18. If there are no errors, then restore the $II_SYSTEM/ingres/files/config.dat and $II_SYSTEM/ingres/files/symbol.tbl files from the copies made in step 6 to replace the existing files.

        19. Start Ingres using the ‘ingstart' utility:


          ingstart

        20. Upgrade the databases in the installation to the new release level:


          upgradedb -all

        Linux:

        1. Log on to the machine as ‘root'.

        2. Copy the downloaded build update file and to a previously chosen directory and uncompress.

        3. Read in the update file with the following command:


          tar xf [update file]


          This creates a directory containing rpm packages for all of the Ingres tools.

        4. Shut down any non-Ingres application(s) that may be connected to or using any of the files in the specified Ingres instance.

        5. Stop all Ingres processes with the ‘ingstop' utility:


          ingstop

        6. Important: Take an operating system backup of the $II_SYSTEM/ingres directory and other DATA locations that you may have elsewhere.

        7. From the directory that was created in step 3, install the update rpms with the following command:


          rpm –Uvh *.rpm


          If the following error is seen for either the ‘ca-ingres-documentation-3.0.3-103', the ‘ca-ingres-CATOSL-3.0.3-103' or the ‘ca-cs-utils-11.0.04348-0000' (or all of them) packages, remove them from the directory containing the rpms and re-run the above command:


          package <package-name> is already installed

        8. If the installation finishes successfully, then log on as ‘ingres' to the machine and start Ingres using the ‘ingstart' utility:


          ingstart

        9. Upgrade ‘mdb' database with the following command:


          upgradedb -all

        For these products:

        CA ARCserve Backup for Unix r11.1
        CA ARCserve Backup for Unix r11.5 GA/SP1/SP2
        CA ARCserve Backup for Unix r11.5 SP3
        CA ARCserve Backup for Linux r11.1
        EEM (eIAM) 8.1
        NSM 3.0 0305
        NSM 3.1 0403
        NSM r3.1 SP1 0703
        Unicenter Service Catalog r2.2
        Unicenter ServicePlus Service Desk 6.0

        Apply the update below that is listed for your platform:

        AIX 32bit [2.6/xxxx (rs4.us5/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12718.tar.Z

        AIX 64bit [2.6/xxxx (r64.us5/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12798.tar.Z

        HP-UX with ARCserve 11.1 or 11.5/GA/SP1/SP2/SP3
        https://support.ca.com/irj/portal/anonymous/solndtls?aparNo=RO01277&os=HP&actionID=3

        HP-UX Itanium [2.6/xxxx (i64.hpu/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12748.tar.Z

        HP-UX RISC 32bit [2.6/xxxx (hpb.us5/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12742.tar.Z

        HP-UX RISC 32bit [2.6/xxxx (hpb.us5/00)DBL]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12888.tar.Z

        HP-UX RISC 64bit [2.6/xxxx (hp2.us5/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12749.tar.Z

        HP Tru64 UNIX [2.6/xxxx (axp.osf/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12676.tar.Z

        Linux AMD64 [2.6/xxxx (a64.lnx/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12809.tar.Z

        Linux Intel 32bit [2.6/xxxx (int.lnx/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12645.tar.Z

        Linux Intel 32bit [2.6/xxxx (int.lnx/00)DBL]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12647.tar.Z

        Linux Intel 32bit [2.6/xxxx (int.lnx/00)LFS]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12646.tar.Z

        Linux Itanium [2.6/xxxx (i64.lnx/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12648.tar.Z

        Linux S/390 [2.6/xxxx (ibm.lnx/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12877.tar.Z

        Solaris SPARC 32bit [2.6/xxxx (su4.us5/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12713.tar.Z

        Solaris SPARC 32bit double [2.6/xxxx (su4.us5/00)DBL]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12879.tar.Z

        Solaris SPARC 64bit [2.6/xxxx (su9.us5/00)]
        https://ftp.broadcom.com/user/downloads/CAproducts/ips/MDB/Generic_Ingres/Patches/2.6/p12751.tar.Z

        Ingres 2.6 Vulnerability Updates Install Steps (August 1, 2008)

        Unix/Linux:

        1. Log on to your system using the installation owner account and make sure the environment is set up correctly:

          1. II_SYSTEM must be set to the Ingres system files

          2. PATH must include $II_SYSTEM/bin and $II_SYSTEM/utility directories.

          3. Change directory to the root directory of the Ingres installation or use a previously created directory.


            cd $II_SYSTEM/ingres


            or


            cd <patch_directory>

          4. Copy the download maintenance update file in to the current directory and uncompress

          5. Read in the update file with the following commands:


            umask 022


            tar xf [update_file]

            This will create the directory:

            $II_SYSTEM/ingres/patchXXXXX

            or

            <patch_directory>/patchXXXXX

            Note: ‘XXXXX' in patchXXXXX refers to the update number

          6. Stop all Ingres processes with the ‘ingstop' utility:

            ingstop

          7. Change directory to the patch directory:

            cd patchXXXXX

          8. Within the patch directory run the following command:

            ./utility/iiinstaller

            Please check the $II_SYSTEM/ingres/files/patch.log file to make sure the patch was applied successfully. Also check the $II_SYSTEM/ingres/version.rel to make sure the patch is referenced.

            Note: The patch can also be installed silently using the ‘-m' flag with iiinstaller:

            ./utility/iiinstaller -m

          9. Once the patch install has been complete, re-link the iimerge binary with the following command:

            iilink

          10. Ingres can then be restarted with the ‘ingstart' utility:

            ingstart

          Workaround

          None.

          References

          CVE-2008-3356 - Ingres verifydb file create permission override.
          CVE-2008-3357 - Ingres un-secure directory privileges with utility ingvalidpw.
          CVE-2008-3389 - Ingres verifydb, iimerge, csreport buffer overflow.

          Acknowledgements

          iDefense Labs

          Change History

          Version 1.0: Initial Release.

          If additional information is required, please contact CA Technical Support at https://support.ca.com.

          If you discover a vulnerability in CA products, please report your findings to our product security response team.