vendor:
InterBase Server
by:
Aviram Jenik
7.5
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: InterBase Server
Affected Version From: Borland Interbase 7.1 SP 2 and lower
Affected Version To: Borland Interbase 7.1 SP 2 and lower
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
Priv8security.com InterBase Server Remote Exploit
This is a remote exploit for Borland Interbase 7.1 SP 2 and lower versions. It allows an attacker to execute arbitrary code on the target system. The exploit was discovered by Aviram Jenik and published on securiteam.com. The exploit works by sending specially crafted buffers to the InterBase server, causing a buffer overflow and allowing the attacker to gain root access. The exploit has been tested on Linux Interbase 7.1 SP 2.
Mitigation:
Upgrade to a patched version of InterBase or apply vendor-supplied patches.