CVE-2007-3527: Integer Overflow
Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain database operations with multi-byte character sets that trigger an attempt to use the value 65536 for a 16-bit integer, which is treated as 0 and causes an infinite loop on zero-length data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3527?
CVE-2007-3527 is classified as a denial of service vulnerability that can lead to high CPU consumption.
How do I fix CVE-2007-3527?
To mitigate CVE-2007-3527, upgrade Firebird to version 2.0.1 or later.
Who is affected by CVE-2007-3527?
CVE-2007-3527 affects remote authenticated users of Firebird 2.0.0 who perform specific database operations.
What happens if CVE-2007-3527 is exploited?
Exploitation of CVE-2007-3527 can result in an infinite loop, causing a Denial of Service by consuming CPU resources.
What version of Firebird should I avoid to prevent CVE-2007-3527?
Users should avoid using Firebird version 2.0.0 to prevent the vulnerabilities associated with CVE-2007-3527.