Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702648
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 2648-1 (firebird2.5 - several vulnerabilities)
Summary:A buffer overflow was discovered in the Firebird database server, which;could result in the execution of arbitrary code. In addition, a denial;of service vulnerability was discovered in the TraceManager.
Description:Summary:
A buffer overflow was discovered in the Firebird database server, which
could result in the execution of arbitrary code. In addition, a denial
of service vulnerability was discovered in the TraceManager.

Affected Software/OS:
firebird2.5 on Debian Linux

Solution:
For the stable distribution (squeeze), these problems have been fixed in
version 2.5.0.26054~
ReleaseCandidate3.ds2-1+squeeze1.

For the testing distribution (wheezy), these problems will be fixed soon.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your firebird2.5 packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-2492
BugTraq ID: 58393
http://www.securityfocus.com/bid/58393
Debian Security Information: DSA-2647 (Google Search)
http://www.debian.org/security/2013/dsa-2647
Debian Security Information: DSA-2648 (Google Search)
http://www.debian.org/security/2013/dsa-2648
https://security.gentoo.org/glsa/201512-11
https://gist.github.com/zeroSteiner/85daef257831d904479c
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/fb_cnct_group.rb
SuSE Security Announcement: openSUSE-SU-2013:0496 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00036.html
SuSE Security Announcement: openSUSE-SU-2013:0504 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00039.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-5529
BugTraq ID: 56521
http://www.securityfocus.com/bid/56521
http://www.openwall.com/lists/oss-security/2012/11/14/6
http://www.openwall.com/lists/oss-security/2012/11/14/8
http://www.securitytracker.com/id?1027769
XForce ISS Database: firebird-tracedsqlprepareprepare-dos(80073)
https://exchange.xforce.ibmcloud.com/vulnerabilities/80073
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.