Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200405-18 ] Buffer Overflow in Firebird
Date: Sun, 23 May 2004 12:14:51
Message-Id: 40B0954A.6020103@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200405-18
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: High
11 Title: Buffer Overflow in Firebird
12 Date: May 23, 2004
13 Bugs: #20837
14 ID: 200405-18
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 A buffer overflow via environmental variables in Firebird may allow a
22 local user to manipulate or destroy local databases and trojan the
23 Firebird binaries.
24
25 Background
26 ==========
27
28 Firebird is an open source relational database that runs on Linux,
29 Windows, and various UNIX systems.
30
31 Affected packages
32 =================
33
34 -------------------------------------------------------------------
35 Package / Vulnerable / Unaffected
36 -------------------------------------------------------------------
37 1 dev-db/firebird < 1.5 >= 1.5
38
39 Description
40 ===========
41
42 A buffer overflow exists in three Firebird binaries (gds_inet_server,
43 gds_lock_mgr, and gds_drop) that is exploitable by setting a large
44 value to the INTERBASE environment variable.
45
46 Impact
47 ======
48
49 An attacker could control program execution, allowing privilege
50 escalation to the UID of Firebird, full access to Firebird databases,
51 and trojaning the Firebird binaries. An attacker could use this to
52 compromise other user or root accounts.
53
54 Workaround
55 ==========
56
57 There is no known workaround.
58
59 Resolution
60 ==========
61
62 All users should upgrade to the latest version of Firebird:
63
64 # emerge sync
65
66 # emerge -pv ">=dev-db/firebird-1.5"
67 # emerge ">=dev-db/firebird-1.5"
68
69 References
70 ==========
71
72 [ 1 ] Bugtraq Security Announcement
73 http://securityfocus.com/bid/7546/info/
74 [ 2 ] Sourceforge BugTracker Announcement
75
76 http://sourceforge.net/tracker/?group_id=9028&atid=109028&func=detail&aid=739480
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200405-18.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2004 Gentoo Technologies, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/1.0
105
106 -----BEGIN PGP SIGNATURE-----
107 Version: GnuPG v1.2.4 (GNU/Linux)
108 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
109
110 iD8DBQFAsJVJvcL1obalX08RAj+PAKCb9Fd0AtIgaUbIj171XyOS2C1KrwCgli71
111 8qHVQCl6dlag+WIA4iPZR7w=
112 =zCcg
113 -----END PGP SIGNATURE-----