Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0387
HistoryJan 29, 2008 - 12:00 a.m.

CVE-2008-0387

2008-01-2900:00:00
ubuntu.com
ubuntu.com
6

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.928

Percentile

99.0%

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6,
2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers
to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3)
op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6)
op_start_send_and_receive XDR requests, which triggers memory corruption.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchfirebird2.0< 2.0.3.12981.ds1-4UNKNOWN
ubuntu8.10noarchfirebird2.0< 2.0.3.12981.ds1-4UNKNOWN
ubuntu9.04noarchfirebird2.0< 2.0.3.12981.ds1-4UNKNOWN
ubuntu9.10noarchfirebird2.0< 2.0.3.12981.ds1-4UNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.928

Percentile

99.0%