LWN.net Logo

firebird: multiple vulnerabilities

Package(s):firebird CVE #(s):CVE-2013-2492 CVE-2012-5529
Created:March 18, 2013 Updated:April 3, 2013
Description: From the CVE entries:

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information. (CVE-2013-2492)

TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query. (CVE-2012-5529)

Alerts:
Debian DSA-2647-1 2013-03-15
Debian DSA-2648-1 2013-03-15
openSUSE openSUSE-SU-2013:0496-1 2013-03-20
openSUSE openSUSE-SU-2013:0504-1 2013-03-20
Fedora FEDORA-2013-3719 2013-03-20
Fedora FEDORA-2013-3707 2013-03-20
Mageia MGASA-2013-0102 2013-04-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds