Descriptionfb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of service (blocked query processing) by locking semaphores.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs362001

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firebird1.5source(unstable)(not affected)
firebird2.0source(unstable)(not affected)


- firebird1.5 <not-affected> (fixed before rename to firebird1.5)
[etch] - firebird2 <no-dsa> (Fixed packages have been released through, see #1529)
- firebird2.0 <not-affected> (fixed in 2.0)
[sarge] - firebird2 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems