Executive Summary
Summary | |
---|---|
Title | New firebird2 packages fix denial of service |
Informations | |||
---|---|---|---|
Name | DSA-1014 | First vendor Publication | 2006-03-23 |
Vendor | Debian | Last vendor Modification | 2006-03-23 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Aviram Jenik and Damyan Ivanov discovered a buffer overflow in firebird2, an RDBMS based on InterBase 6.0 code, that allows remote attackers to crash. The old stable distribution (woody) does not contain firebird2 packages. For the stable distribution (sarge) this problem has been fixed in version 1.5.1-4sarge1. For the unstable distribution (sid) this problem has been fixed in version 1.5.3.4870-3 We recommend that you upgrade your firebird2 packages. |
Original Source
Url : http://www.debian.org/security/2006/dsa-1014 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 1014-1 (firebird2) File : nvt/deb_1014_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
6624 | Borland Interbase Database Name Overflow A remote overflow exists in Borland Interbase. The database fails to do proper bounds checking on the passed database name resulting in a buffer overflow. With a specially crafted request, an attacker can cause execute code on the remote host resulting in a loss of integrity. |
6408 | Firebird Database Remote Database Name Overflow DoS A remote overflow exists in Firebird. The issue is due to improper handling of database names resulting in a buffer overflow. With a specially crafted request, an attacker can cause the server to crash resulting in a loss of availability |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1014.nasl - Type : ACT_GATHER_INFO |
2004-05-25 | Name : It is possible to execute code on the remote host. File : firebird_bo.nasl - Type : ACT_MIXED_ATTACK |
Alert History
Date | Informations |
---|---|
2014-02-17 11:25:35 |
|