|
|
| |
|
| |
firebird: Locally exploitable stack overflow
| Package(s): | firebird |
CVE #(s): | |
| Created: | May 24, 2004 |
Updated: | May 26, 2004 |
| Description: |
A buffer overflow exists in three Firebird database binaries
(gds_inet_server, gds_lock_mgr, and gds_drop) that is exploitable by
setting a large value to the INTERBASE environment variable. An attacker
could control program execution, allowing privilege escalation to the UID
of Firebird, full access to Firebird databases, and trojaning the Firebird
binaries. An attacker could use this to compromise other user or root
accounts. See also this bug
report. |
| Alerts: |
|
( Log in to post comments)
|
|
|