4.6
CVSSv2

CVE-2003-0281

Published: 16/06/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 475
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in Firebird 1.0.2 and other versions prior to 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

Vulnerable Product Search on Vulmon Subscribe to Product

firebirdsql firebird 1.0.2

Exploits

source: wwwsecurityfocuscom/bid/5044/info Interbase is a database distributed and maintained by Borland It is available for Unix and Linux operating systems A buffer overflow has been discovered in the gds_drop program packaged with Interbase This problem could allow a local user to execute the program with strings of arbitrary leng ...
/* DSR-firebirdc ------------------------------- Tested on: Firebird 102 FreeBSD 47-RELEASE This is Proof Of concept code bash-205a$ /DSR-firebird ( ( Firebird-102 Local exploit for Freebsd 47 ) ) ( ( by - bob@dtorsnet ) ) ---------------------------------------------------- Usage: /DSR-firebird <target# ...
source: wwwsecurityfocuscom/bid/5044/info Interbase is a database distributed and maintained by Borland It is available for Unix and Linux operating systems A buffer overflow has been discovered in the gds_drop program packaged with Interbase This problem could allow a local user to execute the program with strings of arbitrary length ...