Firebird Relational Database 2.0.0 Remote Denial Of Service Vulnerability
BID:28473
Info
Firebird Relational Database 2.0.0 Remote Denial Of Service Vulnerability
| Bugtraq ID: | 28473 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3527 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2007 12:00AM |
| Updated: | Mar 27 2008 04:39PM |
| Credit: | Firebird |
| Vulnerable: |
Firebird Firebird 2.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Firebird Firebird 2.0.1 |
Discussion
Firebird Relational Database 2.0.0 Remote Denial Of Service Vulnerability
Firebird is prone to a remote denial-of-service vulnerability that arises because of an integer-overflow condition.
An attacker can exploit this issue to crash the application, denying access to legitimate users.
NOTE: An attacker must be able to successfully authenticate to the database server before exploiting this issue. This may be done through legitimate means or by exploiting other latent SQL-injection vulnerabilities.
This issue affects versions prior to Firebird 2.0.1.
Firebird is prone to a remote denial-of-service vulnerability that arises because of an integer-overflow condition.
An attacker can exploit this issue to crash the application, denying access to legitimate users.
NOTE: An attacker must be able to successfully authenticate to the database server before exploiting this issue. This may be done through legitimate means or by exploiting other latent SQL-injection vulnerabilities.
This issue affects versions prior to Firebird 2.0.1.
Exploit / POC
Firebird Relational Database 2.0.0 Remote Denial Of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Firebird Relational Database 2.0.0 Remote Denial Of Service Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Firebird Relational Database 2.0.0 Remote Denial Of Service Vulnerability
References:
References: