[Forgot Password]
Login  Register Subscribe

23631

 
 

126941

 
 

98250

 
 

909

 
 

79281

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2008-0387

Date: (C)2008-01-28   (M)2017-08-08 


Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

CVSS Score: 7.8Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 6.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: COMPLETE





Reference:
http://www.securityfocus.com/archive/1/archive/1/487173/100/0/threaded
BID-27403
SECUNIA-29203
SECUNIA-29501
SREASON-3580
DSA-1529
GLSA-200803-02
firebird-xdrprotocol-integer-overflow(39996)
http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800
http://tracker.firebirdsql.org/browse/CORE-1681
http://www.coresecurity.com/?action=item&id=2095

CPE    4
cpe:/a:firebirdsql:firebird:1.0.3
cpe:/a:firebirdsql:firebird:2.1_beta
cpe:/a:firebirdsql:firebird:2.0.3
cpe:/a:firebirdsql:firebird:1.5.5
...
CWE    1
CWE-189

© 2013 SecPod Technologies