
<A HREF="http://www.eweek.com/article2/0,1759,2098138,00.asp?kc=EWRSS03119TX1K0000594">IBM has patched some serious flaws</A> affecting users of DB2 Universal Database version 9.1 that could be exploited locally by attackers. A vulnerability in several set-uid DB2 binaries allows a user to write to any file on the system through the use of symbolic links. In addition, local exploitation of another flaw could allow an attacker to elevate privileges to root.