5
CVSSv2

CVE-2009-2620

Published: 29/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 prior to 1.5.6, 2.0 prior to 2.0.6, 2.1 prior to 2.1.3, and 2.5 prior to 2.5 Beta 2 allows remote malicious users to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

firebirdsql firebird 1.5.2

firebirdsql firebird 1.5.2.4731

firebirdsql firebird

firebirdsql firebird 2.0.1

firebirdsql firebird 1.5

firebirdsql firebird 1.5.1

firebirdsql firebird 2.0.0.12748

firebirdsql firebird 2.0.2

firebirdsql firebird 1.5.3.4870

firebirdsql firebird 1.5.4.4910

firebirdsql firebird 2.1

firebirdsql firebird 2.1.2

firebirdsql firebird 2.1.3

firebirdsql firebird 1.5.5

firebirdsql firebird 2.0.0

firebirdsql firebird 2.5

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ Firebird SQL op_connect_request main listener shutdown vulnerability 1 *Advisory Information* Title: Firebird SQL op_connect_request main listener shutdown vulnerability Advisory ID: CORE-2009-070 ...