Vulnerabilities > CVE-2003-0281 - Unspecified vulnerability in Firebirdsql Firebird 1.0.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Firebird 1.0.2 FreeBSD 4.7-RELEASE Local Root Exploit. CVE-2002-2087,CVE-2003-0281. Local exploit for bsd platform id EDB-ID:29 last seen 2016-01-31 modified 2003-05-12 published 2003-05-12 reporter bob source https://www.exploit-db.com/download/29/ title Firebird 1.0.2 FreeBSD 4.7-RELEASE - Local Root Exploit description Interbase 6.0 GDS_Drop Interbase Environment Variable Buffer Overflow (1). CVE-2002-2087,CVE-2003-0281. Local exploit for unix platform id EDB-ID:21565 last seen 2016-02-02 modified 2002-06-15 published 2002-06-15 reporter stripey source https://www.exploit-db.com/download/21565/ title Interbase 6.0 GDS_Drop Interbase Environment Variable Buffer Overflow 1 description Interbase 6.0 GDS_Drop Interbase Environment Variable Buffer Overflow (2). CVE-2002-2087,CVE-2003-0281. Local exploit for unix platform id EDB-ID:21566 last seen 2016-02-02 modified 2002-06-18 published 2002-06-18 reporter bob source https://www.exploit-db.com/download/21566/ title Interbase 6.0 GDS_Drop Interbase Environment Variable Buffer Overflow 2
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200405-18.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200405-18 (Buffer Overflow in Firebird) A buffer overflow exists in three Firebird binaries (gds_inet_server, gds_lock_mgr, and gds_drop) that is exploitable by setting a large value to the INTERBASE environment variable. Impact : An attacker could control program execution, allowing privilege escalation to the UID of Firebird, full access to Firebird databases, and trojaning the Firebird binaries. An attacker could use this to compromise other user or root accounts. Workaround : There is no known workaround. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14504 |
published | 2004-08-30 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/14504 |
title | GLSA-200405-18 : Buffer Overflow in Firebird |
code |
|
References
- http://marc.info/?l=bugtraq&m=105259012802997&w=2
- http://marc.info/?l=bugtraq&m=105259012802997&w=2
- http://seclists.org/lists/bugtraq/2002/Jun/0212.html
- http://seclists.org/lists/bugtraq/2002/Jun/0212.html
- http://secunia.com/advisories/8758
- http://secunia.com/advisories/8758
- http://security.gentoo.org/glsa/glsa-200405-18.xml
- http://security.gentoo.org/glsa/glsa-200405-18.xml
- http://www.securityfocus.com/bid/7546
- http://www.securityfocus.com/bid/7546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11977