Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firebird3.0Upgrade firebird2.5 | Mar 30, 2017 | Mar 24, 2017 |
| Suse | — | Upgrade libfbembed2_5Upgrade libfbembed-develUpgrade firebird-devel | May 3, 2017 | Mar 24, 2017 |
| Ubuntu | — | Upgrade libfbclient2 (Ubuntu Pro)Upgrade libib-util (Ubuntu Pro)Upgrade libfbembed2.5 (Ubuntu Pro)Upgrade firebird2.5-superclassicUpgrade firebird2.5-superUpgrade firebird2.5-classic (Ubuntu Pro)Upgrade firebird2.5-server-commonUpgrade firebird2.5-classic-common (Ubuntu Pro)Upgrade libfbembed2.5Upgrade firebird2.5-server-common (Ubuntu Pro)Upgrade libib-utilUpgrade firebird2.5-classic-commonUpgrade firebird2.5-classicUpgrade firebird2.5-super (Ubuntu Pro)Upgrade firebird2.5-common (Ubuntu Pro)Upgrade firebird2.5-superclassic (Ubuntu Pro)Upgrade libfbclient2 | Apr 4, 2019 | Mar 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub