Title : Firebird 2 Multiple Request Processing Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3379 CVE ID : CVE-2007-4992 - CVE-2007-5245
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-10-05
Technical Description
Multiple vulnerabilities have been identified in Firebird 2, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors in the "isc_attach_database()", "isc_create_database()", and "process_packet()" functions when processing malformed data, which could be exploited by attackers to crash an affected database or execute arbitrary code via a specially crafted request.