OSVDB ID: 38606

Title: Borland InterBase Multiple Function create Request Remote Overflow

Info

Disclosure

Oct 03, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A buffer overflow exists in InterBase. The isc_create_database and jrd8_create_database functions fail to validate 'create' requests resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Borland

Interbase

5.1.1.680
5.5.0.742
6.0.0.627
6.0.1.0
6.0.1.6
6.0.2.0
6.5.0.28
7.0.1.1
7.5.0.129
7.5.1.80
8.0.0.123
8.1.0.257
8.1.0.253
8.0.0.54
8.0.0.53

References

Credit

  • Adriano Lima - adrianorisesecurity.org - RISE Security
  • Ramon de Carvalho Valle - ramonrisesecurity.org - RISE Security


Direct URL: http://osvdb.org/38606