PT-2007-3925 · Firebird · Firebird

Publicado

2007-05-11

·

Atualizado

2018-10-16

·

CVE-2007-2606

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Firebird version 2.1
Description The issue is related to multiple buffer overflows that allow attackers to trigger memory corruption and possibly have other unspecified impact. This is achieved via certain input processed by either the ConfigFile.cpp or check msgs.epp components.
Recommendations For Firebird version 2.1, consider restricting access to configuration files to minimize the risk of exploitation, especially if ConfigFile.cpp is involved in reading these files. As a temporary workaround, review and limit the input processed by ConfigFile.cpp and check msgs.epp to prevent buffer overflows until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2606

Produtos afetados

Firebird