20040602 Firebird [ AND Interbase 7 ] Database Remote Database Name Overflowmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0027.html CVE-2004-2043
Firebird 1.0 - Remote Database Name Buffer Overrun
Record summary
CVE-2004-2043 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBFirebird 1.0 - Remote Database Name Buffer OverrunExploitDB exploitby wsxzNot analyzed1 file
ExploitDBBorland Interbase 7.x - Remote Buffer OverflowExploitDB exploitby Aviram JenikNot analyzed1 file
References
Showing 12 of 1320040601 Firebird Database Remote Database Name Overflowmailing list
http://marc.info/?l=bugtraq&m=108611386202493&w=2 11756Third-party advisory
http://secunia.com/advisories/11756 19350Third-party advisory
http://secunia.com/advisories/19350 1010381vdb entry
http://securitytracker.com/id?1010381 DSA-1014Vendor advisory
http://www.debian.org/security/2006/dsa-1014 6408vdb entry
http://www.osvdb.org/6408 6624vdb entry
http://www.osvdb.org/6624 securiteam.com
http://www.securiteam.com/unixfocus/5AP0P0UCUO.html 10446vdb entry
http://www.securityfocus.com/bid/10446 firebird-database-name-bo(16229)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16229 interbase-database-name-bo(16316)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16316