5
CVSSv2

CVE-2004-2043

Published: 01/05/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in ibserver for Firebird Database 1.0 and other versions prior to 1.5, and possibly other products that use the InterBase codebase, allows remote malicious users to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.

Vulnerable Product Search on Vulmon Subscribe to Product

borland software interbase 5.0

borland software interbase 6.0

borland software interbase 4.0

borland software interbase superserver 6.0

firebirdsql firebird 1.0

borland software interbase 6.4

borland software interbase 6.5

borland software interbase 7.0

borland software interbase 7.1

Exploits

source: wwwsecurityfocuscom/bid/10446/info Firebird is reported prone to a remote buffer-overrun vulnerability The issue occurs because the application fails to perform sufficient boundary checks when the database server is handling database names A remote attacker may exploit this vulnerability, without requiring valid authentication ...
#!/usr/bin/perl # Priv8security com remote exploit for Borland Interbase 71 SP 2 and lower # Public Version!!! # # Bug found by Aviram Jenik wwwsecuriteamcom unixfocus 5AP0P0UCUOhtml # # [wsxz@localhost buffer]$ perl priv8ibserverbpl -h localhost -t 0 # # -=[ Priv8securitycom InterBase Server 71 SP2 and lower remote exploit ]=- # # [+] Using ...