Firebird 'ISC_PASSWORD' Environment Variable Unauthorized Access Vulnerability
BID:29123
Info
Firebird 'ISC_PASSWORD' Environment Variable Unauthorized Access Vulnerability
| Bugtraq ID: | 29123 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1880 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2008 12:00AM |
| Updated: | May 09 2008 06:05PM |
| Credit: | Viesturs |
| Vulnerable: |
Gentoo dev-db/firebird 2.0.3 .12981.0-r5 Firebird Firebird 2.0.3 .12981.0 |
| Not Vulnerable: | |
Discussion
Firebird 'ISC_PASSWORD' Environment Variable Unauthorized Access Vulnerability
Firebird is prone to a vulnerability that can result in unauthorized database access.
Attackers can exploit this issue to gain 'SYSDBA' user access to affected databases.
Firebird 2.0.3.12981.0 is vulnerable; other versions may also be affected.
NOTE: Reports suggest that this issue may affect only Firebird distributions provided in the Gentoo Linux operating platform.
Firebird is prone to a vulnerability that can result in unauthorized database access.
Attackers can exploit this issue to gain 'SYSDBA' user access to affected databases.
Firebird 2.0.3.12981.0 is vulnerable; other versions may also be affected.
NOTE: Reports suggest that this issue may affect only Firebird distributions provided in the Gentoo Linux operating platform.
Exploit / POC
Firebird 'ISC_PASSWORD' Environment Variable Unauthorized Access Vulnerability
Attackers can exploit this issue by remotely connecting to an affected database.
Attackers can exploit this issue by remotely connecting to an affected database.
Solution / Fix
Firebird 'ISC_PASSWORD' Environment Variable Unauthorized Access Vulnerability
Solution:
An advisory and fix are available. Please see the references for more information.
Solution:
An advisory and fix are available. Please see the references for more information.
References
Firebird 'ISC_PASSWORD' Environment Variable Unauthorized Access Vulnerability
References:
References:
- Firebird Homepage (Firebird)
- [ GLSA 200805-06 ] Firebird: Data disclosure (Robert Buchholz
)