CVE-2008-1880

NameCVE-2008-1880
DescriptionThe default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs481389

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firebird2source(unstable)(unfixed)
firebird2.0source(unstable)2.0.3.12981.ds1-14481389

Notes

[etch] - firebird2 <no-dsa> (Firebird 1.5 no longer supported, see last DSA)
on debian after the installation firebird2.0-super is disabled, to enable it
you need to call dpkg-reconfigure

Search for package or bug name: Reporting problems