Vulnerabilities > CVE-2006-1241 - Local Inet_Server Buffer Overflow vulnerability in Firebirdsql Firebird 1.5.2.4731

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
firebirdsql

Summary

Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities. The problems are fixed in the current 1.5.3 version of the Firebird binary distribution.

Vulnerable Configurations

Part Description Count
Application
Firebirdsql
1