Vulnerability Name: | CVE-2003-0281 (CCN-11977) | ||||||||
Assigned: | 2003-05-09 | ||||||||
Published: | 2003-05-09 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri May 09 2003 - 18:57:11 CDT Firebird Local exploit Source: MITRE Type: CNA CVE-2003-0281 Source: BUGTRAQ Type: UNKNOWN 20030509 Firebird Local exploit Source: BUGTRAQ Type: UNKNOWN 20020617 Interbase 6.0 malloc() issues Source: CCN Type: SA8758 Firebird Environment Variable Buffer Overflow Vulnerabilities Source: SECUNIA Type: UNKNOWN 8758 Source: GENTOO Type: UNKNOWN GLSA-200405-18 Source: CCN Type: GLSA-200405-18 Buffer Overflow in Firebird Source: BID Type: UNKNOWN 7546 Source: CCN Type: BID-7546 Firebird GDS_Inet_Server Interbase Environment Variable Buffer Overflow Vulnerability Source: XF Type: UNKNOWN firebird-interbase-bo(11977) Source: XF Type: UNKNOWN firebird-interbase-bo(11977) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |