This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firebird Vuln - Update Available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/25601
Last Update: 2007-06-15
Critical: Moderately critical
Impact: System access
Where: From local network
Solution Status: Vendor Patch
Software: Firebird 2.x
Solution: Update to version 2.0.1…
(Notes: http://www.firebirdsql.org/index.php?op=de…d=fb201_release )

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3181
Last revised: 6/18/2007
Source: US-CERT/NIST
CVSS Severity: 10.0 (High)
Range: Remotely exploitable

:ph34r:
FYI…

Firebird sub-release 2.0.3 (26-Sep-2007)
- http://www.firebirdsql.org/index.php?op=de…d=fb203_release
"This sub-release does not add any new functionality to the database engine. It contains a number of fixes to bugs discovered since the v.2.0.1 sub-release and corrects a regression that caused the withdrawal of the v.2.0.2 sub-release. Minor improvements include a port of Firebird 2.0.3 Classic for MacOSX on Intel and increased access security for the Firebird log."

Download:
- http://sourceforge.net/project/showfiles.php?group_id=9028

—————

> http://secunia.com/advisories/27057/
Release Date: 2007-10-05
Critical: Moderately critical
Impact: System access
Where: From local network
Solution Status: Vendor Patch
…The vulnerabilities are reported in Firebird version WI-V2.0.1.12855, WI-V2.0.0.12748, LI-V2.0.1.12855, and LI-V2.0.0.12748. Other versions may also be affected.
Solution: Update to version 2.0.3.12981…

.
FYI…

- http://secunia.com/advisories/28596/
Release Date: 2008-01-28
Critical: Moderately critical
Impact: DoS, System access
Where: From local network
Solution Status: Vendor Workaround
Software: Firebird 1.x, Firebird 2.x
…The vulnerability affects version 2.1 Beta 2, 2.0.3, 2.0.2, 2.0.0, 1.0.3, 2.1 Beta 1, 2.1 Alpha 1, 2.0.1, and 1.5.4.
Solution: The vulnerability is fixed in version 2.1 RC1.
Provided and/or discovered by: Reported by the vendor…
Original Advisory:
http://tracker.firebirdsql.org/browse/CORE-1603

Also see:
- http://tracker.firebirdsql.org/browse/CORE-1681

.