PT-2007-3925 · Firebird · Firebird
Published
2007-05-11
·
Updated
2018-10-16
·
CVE-2007-2606
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Firebird version 2.1
Description
The issue is related to multiple buffer overflows that allow attackers to trigger memory corruption and possibly have other unspecified impact. This is achieved via certain input processed by either the
ConfigFile.cpp or check msgs.epp components.Recommendations
For Firebird version 2.1, consider restricting access to configuration files to minimize the risk of exploitation, especially if
ConfigFile.cpp is involved in reading these files. As a temporary workaround, review and limit the input processed by ConfigFile.cpp and check msgs.epp to prevent buffer overflows until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firebird