PT-2007-3925 · Firebird · Firebird

Published

2007-05-11

·

Updated

2018-10-16

·

CVE-2007-2606

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Firebird version 2.1
Description The issue is related to multiple buffer overflows that allow attackers to trigger memory corruption and possibly have other unspecified impact. This is achieved via certain input processed by either the ConfigFile.cpp or check msgs.epp components.
Recommendations For Firebird version 2.1, consider restricting access to configuration files to minimize the risk of exploitation, especially if ConfigFile.cpp is involved in reading these files. As a temporary workaround, review and limit the input processed by ConfigFile.cpp and check msgs.epp to prevent buffer overflows until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2606

Affected Products

Firebird