vendor:
Interbase and Firebird
by:
bob@dtors.net
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Interbase and Firebird
Affected Version From: Interbase and Firebird 1.0.2
Affected Version To: Interbase and Firebird 1.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:borland:interbase
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 4.7-RELEASE
2002
Buffer Overflow in Interbase and Firebird
A buffer overflow has been discovered in the gds_drop program packaged with Interbase. This problem could allow a local user to execute the program with strings of arbitrary length. By using a custom crafted string, the attacker could overwrite stack memory, including the return address of a function, and potentially execute arbitrary code.
Mitigation:
Upgrade to the latest version of Interbase and Firebird.