CVE-2017-6369: High severity firebirdsql Firebird vulnerability
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firebird3.0to a version that resolves this vulnerability.Fixed in 3.0.7.33374.ds4-2Fixed in 3.0.7.33374.ds4-2+deb11u1Fixed in 3.0.11.33637.ds4-2+deb12u1Fixed in 3.0.12.ds7-13+deb13u1Fixed in 3.0.13.ds7-2 - Upgrade
Upgrade
Firebirdto a version that resolves this vulnerability.Fixed in 2.5.7 - Upgrade
Upgrade
Firebirdto a version that resolves this vulnerability.Fixed in 3.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6369?
CVE-2017-6369 is considered a high-severity vulnerability due to its potential to allow remote code execution by authenticated users.
How do I fix CVE-2017-6369?
To fix CVE-2017-6369, upgrade Firebird to version 2.5.7 or 3.0.2 or later.
Who is affected by CVE-2017-6369?
CVE-2017-6369 affects Firebird versions 2.5.x before 2.5.7 and 3.0.x before 3.0.2.
What type of vulnerability is CVE-2017-6369?
CVE-2017-6369 is a code execution vulnerability in the UDF subsystem of Firebird.
Can CVE-2017-6369 be exploited remotely?
Yes, CVE-2017-6369 can be exploited remotely by authenticated users.