Firebird Multiple Denial of Service and Information Disclosure Vulnerabilities
BID:30229
Info
Firebird Multiple Denial of Service and Information Disclosure Vulnerabilities
| Bugtraq ID: | 30229 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 14 2008 12:00AM |
| Updated: | Jul 15 2008 11:59PM |
| Credit: | Firebird |
| Vulnerable: |
Firebird Firebird 2.1 Firebird Firebird 2.0.4 Firebird Firebird 2.0.3 Firebird Firebird 2.0.1 Firebird Firebird 1.5.4 Firebird Firebird 1.0.3 Firebird Firebird 2.5.0 Firebird Firebird 2.1.0 RC1 Firebird Firebird 2.1 Beta 2 Firebird Firebird 2.1 Beta 1 Firebird Firebird 2.1 Alpha 1 Firebird Firebird 2.0 |
| Not Vulnerable: |
Firebird Firebird 2.1.1 Firebird Firebird 2.5 Alpha 1 |
Discussion
Firebird Multiple Denial of Service and Information Disclosure Vulnerabilities
Firebird is prone to multiple vulnerabilities, including multiple denial-of-service issues and multiple information-disclosure issues.
Attackers can exploit these issues to crash the application, corrupt memory, or obtain potentially sensitive information.
Firebird 2.0.4 and 2.1.0 are vulnerable; other versions may also be affected.
Firebird is prone to multiple vulnerabilities, including multiple denial-of-service issues and multiple information-disclosure issues.
Attackers can exploit these issues to crash the application, corrupt memory, or obtain potentially sensitive information.
Firebird 2.0.4 and 2.1.0 are vulnerable; other versions may also be affected.
Exploit / POC
Firebird Multiple Denial of Service and Information Disclosure Vulnerabilities
Some of these issues may not require specific exploit code.
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code.
Currently we are not aware of any working exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Firebird Multiple Denial of Service and Information Disclosure Vulnerabilities
Solution:
The vendor released Firebird 2.1.1 to address some of the issues; Firebird 2.5 Alpha 1 fixes all the vulnerabilities. Please see the references for more information.
Firebird Firebird 2.0
Firebird Firebird 2.1 Beta 1
Firebird Firebird 2.1 Alpha 1
Firebird Firebird 2.5.0
Firebird Firebird 2.1 Beta 2
Firebird Firebird 2.1.0 RC1
Firebird Firebird 1.0.3
Firebird Firebird 2.0.1
Firebird Firebird 2.0.3
Firebird Firebird 2.0.4
Firebird Firebird 2.1
Solution:
The vendor released Firebird 2.1.1 to address some of the issues; Firebird 2.5 Alpha 1 fixes all the vulnerabilities. Please see the references for more information.
Firebird Firebird 2.0
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
Firebird Firebird 2.1 Beta 1
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1
Firebird Firebird 2.1 Alpha 1
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1
Firebird Firebird 2.5.0
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
Firebird Firebird 2.1 Beta 2
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1
Firebird Firebird 2.1.0 RC1
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1
Firebird Firebird 1.0.3
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
Firebird Firebird 2.0.1
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
Firebird Firebird 2.0.3
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
Firebird Firebird 2.0.4
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
Firebird Firebird 2.1
-
Firebird Firebird-2.1.1.17910-0.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.1.1.17910-0.tar.b z2?modtime=1216050454&big_mirror=1 -
Firebird Firebird-2.5.0.20343-Alpha1.tar.bz2
http://downloads.sourceforge.net/firebird/Firebird-2.5.0.20343-Alpha1. tar.bz2?modtime=1215944136&big_mirror=1
References
Firebird Multiple Denial of Service and Information Disclosure Vulnerabilities
References:
References:
- CORE-1845 Some standard calls show server installation directory to regular user (Firebird)
- CORE-1884 Random AVs using stored procedures with expressions as default values (Firebird)
- CORE-1887 New created databases have wrong access rights (Firebird)
- CORE-1919 Memory corruptions in EXECUTE STATEMENT may crash the server (Firebird)
- CORE-1930 Possible AV in engine if procedure was altered to have no outputs and (Firebird)
- Firebird 2.1.1-Release (Source) Changelog (Firebird)
- Firebird Homepage (Firebird)