>> Firebird "fbserver" Service Connect Request Handling Buffer Overflow Vulnerability
Title : Firebird "fbserver" Service Connect Request Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2149 CVE ID : CVE-2007-3181
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-12
Technical Description
A vulnerability has been identified in Firebird, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "fbserver.exe" service (port 3050/TCP) when processing a "connect" request (0x1) with a large "p_cnct_count" value, which could be exploited by remote unauthenticated attackers to crash an affected application or execute arbitrary code with the privileges of the database.