Name | CVE-2012-5529 |
Description | TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-2648-1 |
Debian Bugs | 693210 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
firebird2.1 | source | (unstable) | (not affected) | |||
firebird2.5 | source | squeeze | 2.5.0.26054~ReleaseCandidate3.ds2-1+squeeze1 | DSA-2648-1 | ||
firebird2.5 | source | (unstable) | 2.5.2~svn+54698.ds4-2 | low | 693210 |
- firebird2.1 <not-affected> (Only affects 2.5.x)