Missing Authorization in Firebird - CVE-2017-6369

 

Missing Authorization in Firebird - CVE-2017-6369

Published: March 24, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39386
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6369
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.


Affected software

Firebird
Fedora
firebird

How to mitigate CVE-2017-6369

Install update from vendor's website.

firebird - addressed in versions 2.5.7.27050.0-1.el6, 2.5.7.27050.0-1.el7, 2.5.7.27050.0-1.fc24, 2.5.7.27050.0-1.fc25

External References

Related Security Bulletins