Lucene search

K
saintSAINT CorporationSAINT:339D6F8E49AE64447A9A0D587064BB87
HistoryFeb 11, 2008 - 12:00 a.m.

Firebird username buffer overflow

2008-02-1100:00:00
SAINT Corporation
my.saintcorporation.com
15

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.183

Percentile

96.3%

Added: 02/11/2008
CVE: CVE-2008-0467
BID: 27467
OSVDB: 40924

Background

Firebird is a freely available relational database which is available for multiple platforms.

Problem

A buffer overflow vulnerability in Firebird allows remote, unauthenticated attackers to execute arbitrary commands by sending a long, specially crafted username.

Resolution

Upgrade to Firebird 2.1 RC1 or higher.

References

<http://secunia.com/advisories/28596&gt;

Limitations

Exploit works on Firebird 2.0.3.

Platforms

Windows 2000
Windows Server 2003

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.183

Percentile

96.3%