Fedora 24 update for firebird



| Updated: 2025-04-24
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-6369
CWE-ID CWE-862
Exploitation vector Network
Public exploit N/A
Vulnerable software
Fedora
Operating systems & Components / Operating system

firebird
Operating systems & Components / Operating system package or component

Vendor Fedoraproject

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Missing Authorization

EUVDB-ID: #VU39386

Risk: High

CVSSv4.0: 6.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2017-6369

CWE-ID: CWE-862 - Missing Authorization

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to execute arbitrary code.

Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Fedora: 24

firebird: before 2.5.7.27050.0-1.fc24

CPE2.3 External links

https://bodhi.fedoraproject.org/updates/FEDORA-2017-97d7758431


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###