CVE-2007-4669: Infoleak
Published Sep 4, 2007
·Updated
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
Affected Software
1 affected component
firebirdsql Firebird<=2.0.1
Remediation
Patch Available
Event History
Sep 4, 2007
CVE Published
10:17 PM
Sep 5, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4669?
CVE-2007-4669 is classified as a medium severity vulnerability due to the potential for unauthorized reading of sensitive server log information.
2
How do I fix CVE-2007-4669?
To fix CVE-2007-4669, upgrade to Firebird version 2.0.2 or later where the vulnerability is addressed.
3
Who is affected by CVE-2007-4669?
CVE-2007-4669 affects remote authenticated users of Firebird versions prior to 2.0.2 who do not have SYSDBA privileges.
4
What is the impact of CVE-2007-4669?
The impact of CVE-2007-4669 includes unauthorized access to the server log (firebird.log), which may contain sensitive information.
5
What versions of Firebird are affected by CVE-2007-4669?
CVE-2007-4669 affects all Firebird versions prior to 2.0.2.