First published: Sat Oct 06 2007(Updated: )
Multiple stack-based buffer overflows in Firebird LI 1.5.3.4870 and 1.5.4.4910, and WI 1.5.3.4870 and 1.5.4.4910, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the SVC_attach function or (2) unspecified vectors involving the INET_connect function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FirebirdSQL | =1.5.4.4910 | |
FirebirdSQL | =1.5.3.4870 | |
FirebirdSQL | =1.5.3.4870 | |
FirebirdSQL | =1.5.4.4910 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5245 is considered a critical vulnerability due to its ability to allow remote code execution.
To address CVE-2007-5245, upgrade to Firebird versions 1.5.5 or later which include patches for this vulnerability.
CVE-2007-5245 affects Firebird versions 1.5.3.4870 and 1.5.4.4910 on both Linux and Windows platforms.
Attackers can exploit CVE-2007-5245 to execute arbitrary code on affected machines through manipulated service attach requests.
CVE-2007-5245 is a remote vulnerability, allowing attackers to exploit it over a network without local access.