firebird: multiple vulnerabilities
| Package(s): | firebird | CVE #(s): | CVE-2013-2492 CVE-2012-5529 | ||||||||||||||||||||||||||||||||
| Created: | March 18, 2013 | Updated: | December 30, 2015 | ||||||||||||||||||||||||||||||||
| Description: | From the CVE entries:
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information. (CVE-2013-2492) TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query. (CVE-2012-5529) | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
