Secunia Advisory SA8557

Firebird External Table Vulnerability
Secunia Advisory SA8557
Track and eliminate the complete Vulnerability threat lifecycle

-

Track critical vulnerabilities affecting your infrastucture instantly
Release Date 2003-04-09
   
Popularity 6,318 views
Comments 0 comments

Criticality level Moderately criticalModerately critical
Impact Manipulation of data
Privilege escalation
System access
Where From local network
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Unpatched
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
   
Software:
Firebird 1.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.

  

Description
A vulnerability identified in Firebird can reportedly in worst case be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused by an access control error. The problem is that it is possible to create an external table in an arbitrary file on the system. If the file exists, it is possible to manipulate it by appending data to it. Reportedly, successful exploitation doesn't require that the user has been authenticated.

An example was included in the original advisory, which creates a user with root privileges and no password:

create table test external '/etc/passwd' (id char(80));
insert into test values('r00t::0:0:root:/root:/bin/bash');

The vulnerability has been confirmed in version 1.0.2. It is currently not known whether version 1.5. Beta is vulnerable.

Solution
Allow only trusted users access to the system. Filter traffic to the ports, which Firebird is listening on.

Provided and/or discovered by
Kotala Zdenek

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: Firebird External Table Vulnerability
 
No posts yet

-

You must be logged in to post a comment.



footer
© 2002-2010 Secunia ApS • Weidekampsgade 14A, DK-2300 Copenhagen S, Denmark • +45 7020 5144 • Contact Us
Terms & Conditions and CopyrightReport vulnerability
CVE logo OTA logo First logo