CVE-2013-2492: Buffer Overflow
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2492?
CVE-2013-2492 has been classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2013-2492?
To fix CVE-2013-2492, update Firebird to a version that is not affected, such as Firebird 2.1.5 after patch 18514 or Firebird 2.5.3 after patch 26623.
Which versions of Firebird are affected by CVE-2013-2492?
CVE-2013-2492 affects Firebird versions 2.1.3 to 2.1.5 before 18514 and 2.5.1 to 2.5.3 before 26623.
Can CVE-2013-2492 be exploited remotely?
Yes, CVE-2013-2492 can be exploited remotely through crafted packets sent to TCP port 3050.
What type of vulnerability is CVE-2013-2492?
CVE-2013-2492 is characterized as a stack-based buffer overflow vulnerability.