PT-2007-6329 · Firebird · Firebird

Adriano Lima

+1

·

Published

2007-10-06

·

Updated

2018-10-15

·

CVE-2007-5246

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Firebird LI versions 2.0.0.12748 through 2.0.1.12855 Firebird WI versions 2.0.0.12748 through 2.0.1.12855
Description: The issue allows remote attackers to execute arbitrary code via a long attach request on TCP port 3050 to the isc attach database function or a long create request on TCP port 3050 to the isc create database function. This is due to multiple stack-based buffer overflows.
Recommendations: For Firebird LI versions 2.0.0.12748 through 2.0.1.12855, consider restricting access to TCP port 3050 until a patch is available. For Firebird WI versions 2.0.0.12748 through 2.0.1.12855, consider restricting access to TCP port 3050 until a patch is available. As a temporary workaround, consider disabling the isc attach database and isc create database functions until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5246

Affected Products

Firebird