CVE-2008-0387: Integer Overflow
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) opreceive, (2) opstart, (3) opstartandreceive, (4) opsend, (5) opstartandsend, and (6) opstartsendandreceive XDR requests, which triggers memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0387?
CVE-2008-0387 is rated as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2008-0387?
To fix CVE-2008-0387, you should upgrade Firebird SQL to version 1.5.6 or later, 2.0.4 or later, or 2.1.0 RC1 or later.
What types of operations are affected by CVE-2008-0387?
CVE-2008-0387 affects operations such as op_receive, op_start, op_start_and_receive, op_send, op_start_and_send, and op_start_send.
Which versions of Firebird are vulnerable to CVE-2008-0387?
Firebird SQL versions 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 are vulnerable to CVE-2008-0387.
Can CVE-2008-0387 be exploited remotely?
Yes, CVE-2008-0387 can be exploited by remote attackers, allowing them to execute arbitrary code.