vendor:
Firebird
by:
bob@dtors.net
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Firebird
Affected Version From: Firebird 1.0.0
Affected Version To: Firebird 1.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:firebird:firebird:1.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD
2002
Buffer Overflow in Firebird/Interbase gds_inet_server
A buffer overflow has been discovered in the setuid root program gds_inet_server, packaged with Firebird. This problem could allow a local user to execute the program with strings of arbitrary length. By using a custom crafted string, the attacker could overwrite stack memory, including the return address of a function, and potentially execute arbitrary code as root.
Mitigation:
Upgrade to the latest version of Firebird/Interbase