PT-2008-3410 · Firebird · Firebird

Viesturs

·

Published

2008-05-12

·

Updated

2017-08-08

·

CVE-2008-1880

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firebird versions prior to 2.0.3.12981.0-r6
Description The default configuration of Firebird sets the ISC PASSWORD environment variable before starting Firebird, allowing remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.
Recommendations For versions prior to 2.0.3.12981.0-r6, update to version 2.0.3.12981.0-r6 or later to resolve the issue. As a temporary workaround, consider removing the ISC PASSWORD environment variable to prevent attackers from bypassing SYSDBA authentication.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1880

Affected Products

Firebird