Firebird Remote Pre-Authentication Database Name Buffer Overrun Vulnerability
BID:10446
Info
Firebird Remote Pre-Authentication Database Name Buffer Overrun Vulnerability
| Bugtraq ID: | 10446 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-2043 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2004 12:00AM |
| Updated: | Dec 12 2006 10:48PM |
| Credit: | Discovery of this vulnerability is credited to Aviram Jenik <[email protected]>. |
| Vulnerable: |
Firebird Firebird 1.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Borland/Inprise InterBase SuperServer 6.0 Borland/Inprise Interbase 7.1 Borland/Inprise Interbase 7.0 Borland/Inprise Interbase 6.5 Borland/Inprise Interbase 6.4 Borland/Inprise Interbase 6.0 Borland/Inprise Interbase 5.0 Borland/Inprise Interbase 4.0 |
| Not Vulnerable: |
Firebird Firebird 1.5 |
Discussion
Firebird Remote Pre-Authentication Database Name Buffer Overrun Vulnerability
Firebird is reported prone to a remote buffer-overrun vulnerability. The issue occurs because the application fails to perform sufficient boundary checks when the database server is handling database names.
A remote attacker may exploit this vulnerability, without requiring valid authentication credentials, to influence the execution flow of the affected Firebird database server. Ultimately, this may lead to the execution of attacker-supplied code in the context of the affected software.
Firebird is reported prone to a remote buffer-overrun vulnerability. The issue occurs because the application fails to perform sufficient boundary checks when the database server is handling database names.
A remote attacker may exploit this vulnerability, without requiring valid authentication credentials, to influence the execution flow of the affected Firebird database server. Ultimately, this may lead to the execution of attacker-supplied code in the context of the affected software.
Exploit / POC
Firebird Remote Pre-Authentication Database Name Buffer Overrun Vulnerability
The following example is available:
gsec -database 192.168.1.52:`perl -e'print ("A"x300)'` -user whenever -password whatever
An exploit (priv8ibserverb.pl) that can target Borland Interbase 7.1 SP 2 and lower has been made available by Priv8security.
The following example is available:
gsec -database 192.168.1.52:`perl -e'print ("A"x300)'` -user whenever -password whatever
An exploit (priv8ibserverb.pl) that can target Borland Interbase 7.1 SP 2 and lower has been made available by Priv8security.
Solution / Fix
Firebird Remote Pre-Authentication Database Name Buffer Overrun Vulnerability
Solution:
The vendor has released an upgrade. Reportedly, this upgrade is not prone to this vulnerability.
Please see the references for more information and fixes.
Firebird Firebird 1.0
Solution:
The vendor has released an upgrade. Reportedly, this upgrade is not prone to this vulnerability.
Please see the references for more information and fixes.
Firebird Firebird 1.0
-
Firebird Firebird V1.5 Downloads
http://firebird.sourceforge.net/index.php?op=files&id=engine
References
Firebird Remote Pre-Authentication Database Name Buffer Overrun Vulnerability
References:
References:
- Firebird Homepage (Firebird)