First published: Tue Sep 04 2007(Updated: )
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FirebirdSQL | <=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4669 is classified as a medium severity vulnerability due to the potential for unauthorized reading of sensitive server log information.
To fix CVE-2007-4669, upgrade to Firebird version 2.0.2 or later where the vulnerability is addressed.
CVE-2007-4669 affects remote authenticated users of Firebird versions prior to 2.0.2 who do not have SYSDBA privileges.
The impact of CVE-2007-4669 includes unauthorized access to the server log (firebird.log), which may contain sensitive information.
CVE-2007-4669 affects all Firebird versions prior to 2.0.2.