PT-2014-1959 · Firebird+2 · Firebird+2

Dmitry Kovalenko

·

Published

2014-12-16

·

Updated

2021-03-05

·

CVE-2014-9323

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Firebird versions 2.1.x through 2.1.6 Firebird versions 2.5.x through 2.5.2
Description The issue is related to the xdr status vector function and is caused by pointer dereference errors. It allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference, segmentation fault, and crash, via an op response action with a non-empty status.
Recommendations For Firebird versions 2.1.x through 2.1.6, update to version 2.1.7 or later. For Firebird versions 2.5.x through 2.5.2, update to version 2.5.3 SU1 or later. As a temporary workaround, consider restricting access to the xdr status vector function until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2493
BDU:2015-11679
CVE-2014-9323
DLA-123-1
DLA-130-1
DSA-3109-1
USN-3929-1

Affected Products

Alt Linux
Firebird
Ubuntu