First published: Fri Mar 24 2017(Updated: )
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firebird3.0 | 3.0.7.33374.ds4-2 3.0.11.33637.ds4-2 3.0.11.33703.ds4-4 | |
FirebirdSQL | =2.5.1 | |
FirebirdSQL | =2.5.2 | |
FirebirdSQL | =2.5.3 | |
FirebirdSQL | =2.5.4 | |
FirebirdSQL | =2.5.5 | |
FirebirdSQL | =2.5.6 | |
FirebirdSQL | =3.0 | |
FirebirdSQL | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6369 is considered a high-severity vulnerability due to its potential to allow remote code execution by authenticated users.
To fix CVE-2017-6369, upgrade Firebird to version 2.5.7 or 3.0.2 or later.
CVE-2017-6369 affects Firebird versions 2.5.x before 2.5.7 and 3.0.x before 3.0.2.
CVE-2017-6369 is a code execution vulnerability in the UDF subsystem of Firebird.
Yes, CVE-2017-6369 can be exploited remotely by authenticated users.