Vulnerability Name: | CVE-2008-0387 (CCN-39996) | ||||||||
Assigned: | 2008-01-28 | ||||||||
Published: | 2008-01-28 | ||||||||
Updated: | 2018-10-26 | ||||||||
Summary: | Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-189 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Mar 09 2008 - 08:02:19 CDT Firebird remote BOF POC Source: MITRE Type: CNA CVE-2008-0387 Source: CCN Type: Full-Disclosure Mailing List, Mon, 28 Jan 2008 15:32:00 -0200 CORE-2007-1219: Firebird Remote Memory Corruption Source: SECUNIA Type: Third Party Advisory 29203 Source: CCN Type: SA29501 Debian firebird2 Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 29501 Source: GENTOO Type: Third Party Advisory GLSA-200803-02 Source: SREASON Type: Third Party Advisory 3580 Source: CCN Type: SourceForge.net: Files Firebird Release Name: 2.1 RC1 Source: CONFIRM Type: Third Party Advisory http://sourceforge.net/project/shownotes.php?group_id=9028&release_id=570800 Source: CCN Type: Firebird Bug Tracker CORE-1681 Garbage data in the incoming remote packet may crash the server Source: CONFIRM Type: Vendor Advisory http://tracker.firebirdsql.org/browse/CORE-1681 Source: MISC Type: Third Party Advisory http://www.coresecurity.com/?action=item&id=2095 Source: DEBIAN Type: Third Party Advisory DSA-1529 Source: DEBIAN Type: DSA-1529 firebird -- multiple vulnerabilities Source: CCN Type: Firebird Web site Firebird Source: CCN Type: GLSA-200803-02 Firebird: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 43187 Firebird SQL Multiple XDR Requests Remote Memory Corruption Overflow Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20080128 CORE-2007-1219: Firebird Remote Memory Corruption Source: BID Type: Third Party Advisory, VDB Entry 27403 Source: CCN Type: BID-27403 Firebird Relational Database 'protocol.cpp' XDR Protocol Remote Memory Corruption Vulnerability Source: XF Type: Third Party Advisory, VDB Entry firebird-xdrprotocol-integer-overflow(39996) Source: XF Type: UNKNOWN firebird-xdrprotocol-integer-overflow(39996) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |