Multiple buffer overflows in Firebird 2.1 allow attackers to trigger...
Vulnerability Description
Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact via certain input processed by (1) config\ConfigFile.cpp or (2) msgs\check_msgs.epp. NOTE: if ConfigFile.cpp reads a configuration file with restrictive permissions, then the ConfigFile.cpp vector may not cross privilege boundaries and perhaps should not be included in CVE.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2606
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/37309
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34201
- http://www.securityfocus.com/archive/1/468070/100/0/threaded
- http://www.securityfocus.com/bid/28478
- http://osvdb.org/37308
- http://securityreason.com/securityalert/2708
- http://secunia.com/advisories/29501
- http://www.debian.org/security/2008/dsa-1529
More from firebirdsql
View All →Affected Vendor
firebirdsql
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.