Borland InterBase IBServer.EXE Remote Stack Based Buffer Overflow Vulnerability
BID:25048
Info
Borland InterBase IBServer.EXE Remote Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 25048 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3566 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2007 12:00AM |
| Updated: | Nov 26 2009 07:45PM |
| Credit: | Cody Pierce of TippingPoint DVLabs is credited with the discovery of this issue. |
| Vulnerable: |
Borland/Inprise Interbase 2007 |
| Not Vulnerable: |
Borland/Inprise Interbase 2007 SP2 |
Discussion
Borland InterBase IBServer.EXE Remote Stack Based Buffer Overflow Vulnerability
Borland InterBase is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
Borland InterBase is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Borland InterBase IBServer.EXE Remote Stack Based Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit is available to members of the Immunity Partner's program:
https://www.immunityinc.com/downloads/immpartners/borland_ib.tar
A Metasploit Framework exploit module ('25048.rb') is available.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit is available to members of the Immunity Partner's program:
https://www.immunityinc.com/downloads/immpartners/borland_ib.tar
A Metasploit Framework exploit module ('25048.rb') is available.
Solution / Fix
Borland InterBase IBServer.EXE Remote Stack Based Buffer Overflow Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Borland InterBase IBServer.EXE Remote Stack Based Buffer Overflow Vulnerability
References:
References:
- Borland Homepage (Borland)
- InterBase - Registered Users (Updates for owners of purchased products) (Borland)
- TPTI-07-13: Borland Interbase ibserver.exe Create-Request Buffer Overflow Vulner (Tipping Point)
- TPTI-07-13: Borland Interbase ibserver.exe Create-Request Buffer Overflow Vulner (Tipping Point)