Summary
The remote host is missing updates announced in
advisory GLSA 200805-06.
Solution
All Firebird users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=dev-db/firebird-2.0.3.12981.0-r6'
Note: /etc/conf.d is protected by Portage as a configuration directory. Do not forget to use ' etc-update ' or ' dispatch-conf ' to overwrite the 'firebird' configuration file, and then restart Firebird.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200805-06 http://bugs.gentoo.org/show_bug.cgi?id=216158
Insight
Firebird allows remote connections to the administrative account without verifying credentials.
Severity
Classification
-
CVE CVE-2008-1880 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities