OSVDB ID: 38607

Title: Borland InterBase Multiple Function attach Request Remote Overflow

Info

Disclosure

Oct 03, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A buffer overflow exists in InterBase. The isc_attach_database and PWD_db_Aliased functions fail to validate data received on TCP port 3050 resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Borland

Interbase

5.1.1.680
5.5.0.742
6.0.0.627
6.0.1.0
6.0.1.6
6.0.2.0
6.5.0.28
7.0.1.1
7.5.0.129
7.5.1.80
8.0.0.123
8.1.0.257
8.1.0.253
8.0.0.54
8.0.0.53

References

Credit

  • Adriano Lima - adrianorisesecurity.org - RISE Security
  • Ramon de Carvalho Valle - ramonrisesecurity.org - RISE Security


Direct URL: http://osvdb.org/38607