[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96078

 
 

909

 
 

78009

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2008-0387

Date: (C)2008-01-28   (M)2017-08-08
 
CVSS Score: 7.8Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 6.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: COMPLETE











Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

Reference:
http://www.securityfocus.com/archive/1/archive/1/487173/100/0/threaded
BID-27403
SECUNIA-29203
SECUNIA-29501
SREASON-3580
DSA-1529
GLSA-200803-02
firebird-xdrprotocol-integer-overflow(39996)
http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800
http://tracker.firebirdsql.org/browse/CORE-1681
http://www.coresecurity.com/?action=item&id=2095

CPE    4
cpe:/a:firebirdsql:firebird:1.0.3
cpe:/a:firebirdsql:firebird:2.1_beta
cpe:/a:firebirdsql:firebird:2.0.3
cpe:/a:firebirdsql:firebird:1.5.5
...
CWE    1
CWE-189

© 2013 SecPod Technologies