Vulnerabilities > CVE-2007-3566 - Remote Stack Based Buffer Overflow vulnerability in Borland Software Interbase 2007

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
borland-software
exploit available
metasploit

Summary

Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a create request to port 3050/tcp.

Vulnerable Configurations

Part Description Count
Application
Borland_Software
1

Exploit-Db

descriptionBorland Interbase Create-Request Buffer Overflow. CVE-2007-3566. Remote exploit for windows platform
idEDB-ID:16453
last seen2016-02-01
modified2010-06-15
published2010-06-15
reportermetasploit
sourcehttps://www.exploit-db.com/download/16453/
titleBorland Interbase Create-Request Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in Borland Interbase 2007. By sending a specially crafted create-request packet, a remote attacker may be able to execute arbitrary code.
idMSF:EXPLOIT/WINDOWS/MISC/BORLAND_INTERBASE
last seen2020-06-13
modified2017-07-24
published2007-07-26
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/misc/borland_interbase.rb
titleBorland Interbase Create-Request Buffer Overflow

Packetstorm

Saint

bid25048
descriptionBorland Interbase ibserver.exe create buffer overflow
iddatabase_interbasebo
osvdb38602
titleinterbase_create
typeremote