CVE-2017-11509: SQL Injection
Published Mar 28, 2018
·Updated
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
Affected Software
5 affected components
firebirdsql Firebird=2.5.7
firebirdsql Firebird=3.0.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Mar 28, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11509?
CVE-2017-11509 has a critical severity rating as it allows authenticated remote attackers to execute arbitrary code.
2
How do I fix CVE-2017-11509?
To remediate CVE-2017-11509, update your Firebird SQL Server to versions 2.5.8 or 3.0.3 or later.
3
Which versions of Firebird SQL Server are affected by CVE-2017-11509?
CVE-2017-11509 affects Firebird SQL Server versions 2.5.7 and 3.0.2.
4
Can CVE-2017-11509 affect Debian distributions?
Yes, CVE-2017-11509 can affect Debian Linux versions 7.0, 8.0, and 9.0 if Firebird SQL Server is installed.
5
What type of attack does CVE-2017-11509 enable?
CVE-2017-11509 enables authenticated remote code execution through the execution of a malformed SQL statement.