Name | CVE-2017-11509 |
Description | An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1374-1, DLA-2129-1, DLA-2824-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
firebird3.0 (PTS) | bullseye | 3.0.7.33374.ds4-2 | fixed |
| bookworm | 3.0.11.33637.ds4-2 | fixed |
| sid, trixie | 3.0.11.33703.ds4-4 | fixed |
The information below is based on the following data on fixed versions.
Notes
https://www.tenable.com/security/research/tra-2017-36
https://github.com/FirebirdSQL/firebird/issues/5787
Firebird upstream responded to Tenable the issue is not intended to be addressed
in "any current release".
Issue adressed by disabling UDFs in firebird.conf, this is not a source code fix,
and might actually be considered more of just a mitigation.
Steps to reproduce (partly) in: https://lists.debian.org/874lk9wyz5.fsf@curie.anarc.at