Interbase GDS_Lock_MGR Interbase_Lock Environment Variable Buffer Overflow Vulnerability
BID:7266
Info
Interbase GDS_Lock_MGR Interbase_Lock Environment Variable Buffer Overflow Vulnerability
| Bugtraq ID: | 7266 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 03 2003 12:00AM |
| Updated: | Apr 03 2003 12:00AM |
| Credit: | Discovery credited to Secure Network Operations, Inc. |
| Vulnerable: |
Firebird Firebird 1.0.2 Borland/Inprise Interbase 6.5 Borland/Inprise Interbase 6.4 Borland/Inprise Interbase 6.0 |
| Not Vulnerable: | |
Discussion
Interbase GDS_Lock_MGR Interbase_Lock Environment Variable Buffer Overflow Vulnerability
A buffer overflow has been discovered in the setuid root program gds_lock_mgr, packaged with Interbase. This problem could allow a local user to execute the program with strings of arbitrary length. By using a custom crafted string, the attacker could overwrite stack memory, including the return address of a function, and potentially execute arbitrary code as root.
Firebird is based on Borland/Inprise Interbase source code and is therefore also prone to this issue.
A buffer overflow has been discovered in the setuid root program gds_lock_mgr, packaged with Interbase. This problem could allow a local user to execute the program with strings of arbitrary length. By using a custom crafted string, the attacker could overwrite stack memory, including the return address of a function, and potentially execute arbitrary code as root.
Firebird is based on Borland/Inprise Interbase source code and is therefore also prone to this issue.
Exploit / POC
Interbase GDS_Lock_MGR Interbase_Lock Environment Variable Buffer Overflow Vulnerability
It has been stated that a working proof of concept has developed. However, this proof of concept code has not been publicly released.
It has been stated that a working proof of concept has developed. However, this proof of concept code has not been publicly released.
Solution / Fix
Interbase GDS_Lock_MGR Interbase_Lock Environment Variable Buffer Overflow Vulnerability
Solution:
It has been reported that a patch for version 1.0.2 is pending. The vendor is also reportedly investigating this issue for version 1.5 beta 4.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that a patch for version 1.0.2 is pending. The vendor is also reportedly investigating this issue for version 1.5 beta 4.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Interbase GDS_Lock_MGR Interbase_Lock Environment Variable Buffer Overflow Vulnerability
References:
References:
- Firebird Homepage (Firebird)
- Re: SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow (Marius Popa Adrian
) - SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow (KF
)