Firebird Username Remote Buffer Overflow Vulnerability
BID:27467
Info
Firebird Username Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27467 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0467 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2008 12:00AM |
| Updated: | Mar 27 2008 01:39PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Gentoo Linux Firebird Firebird 2.0.3 Firebird Firebird 2.0.1 Firebird Firebird 1.5.4 Firebird Firebird 1.0.3 Firebird Firebird 2.5.0 Firebird Firebird 2.1 Beta 2 Firebird Firebird 2.1 Beta 1 Firebird Firebird 2.1 Alpha 1 Firebird Firebird 2.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Firebird Firebird 2.0.4 Firebird Firebird 2.1.0 RC1 |
Discussion
Firebird Username Remote Buffer Overflow Vulnerability
Firebird is prone to a remote stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected database server. Failed exploit attempts will likely cause denial-of-service conditions.
The issue affects the following versions:
Firebird 1.5.4
Firebird 2.0
Firebird 2.0.1
Firebird 2.0.2
Firebird 2.0.3
Firebird 2.1 Alpha 1
Firebird 2.1 Beta 1
Firebird 2.1 Beta 2
Firebird is prone to a remote stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected database server. Failed exploit attempts will likely cause denial-of-service conditions.
The issue affects the following versions:
Firebird 1.5.4
Firebird 2.0
Firebird 2.0.1
Firebird 2.0.2
Firebird 2.0.3
Firebird 2.1 Alpha 1
Firebird 2.1 Beta 1
Firebird 2.1 Beta 2
Exploit / POC
Firebird Username Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Firebird Username Remote Buffer Overflow Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Firebird Firebird 2.1 Alpha 1
Firebird Firebird 2.1 Beta 1
Firebird Firebird 2.1 Beta 2
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Firebird Firebird 2.1 Alpha 1
-
Firebird Firebird-2.1.0.17735-ReleaseCandidate1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.0.17735-Release Candidate1.tar.bz2
Firebird Firebird 2.1 Beta 1
-
Firebird Firebird-2.1.0.17735-ReleaseCandidate1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.0.17735-Release Candidate1.tar.bz2
Firebird Firebird 2.1 Beta 2
-
Firebird Firebird-2.1.0.17735-ReleaseCandidate1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.0.17735-Release Candidate1.tar.bz2
References
Firebird Username Remote Buffer Overflow Vulnerability
References:
References:
- CORE-1603: Possible buffer overflow with long user name (Firebird)
- Firebird Homepage (Firebird)
- Firebird Release Notes 2.1 RC1 (Firebird)