Summary
Dmitry Kovalenko discovered that
the Firebird database server is prone to a denial of service vulnerability.
An unauthenticated remote attacker could send a malformed network packet to a firebird server, which would cause the server to crash.
Solution
For the stable distribution (wheezy),
this problem has been fixed in version 2.5.2.26540.ds4-1~deb7u2.
For the upcoming stable distribution (jessie), this problem has been fixed in version 2.5.3.26778.ds4-5.
For the unstable distribution (sid), this problem has been fixed in version 2.5.3.26778.ds4-5.
We recommend that you upgrade your firebird2.5 packages.
Insight
Firebird is a relational database
offering many ANSI SQL-99 features that runs on Linux, Windows, and a variety of Unix platforms. Firebird offers excellent concurrency, high performance, and powerful language support for stored procedures and triggers.
Affected
firebird2.5 on Debian Linux
Detection
This check tests the installed software
version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-9323 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities