Name | CVE-2008-1880 |
Description | The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 481389 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
firebird2 | source | (unstable) | (unfixed) | | | |
firebird2.0 | source | (unstable) | 2.0.3.12981.ds1-14 | | | 481389 |
Notes
[etch] - firebird2 <no-dsa> (Firebird 1.5 no longer supported, see last DSA)
on debian after the installation firebird2.0-super is disabled, to enable it
you need to call dpkg-reconfigure