Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-1880

Опубликовано: 12 мая 2008
Источник: debian

Описание

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firebird2removedpackage
firebird2no-dsaetchpackage
firebird2.0fixed2.0.3.12981.ds1-14package

Примечания

  • on debian after the installation firebird2.0-super is disabled, to enable it

  • you need to call dpkg-reconfigure

Связанные уязвимости

ubuntu
больше 17 лет назад

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.

nvd
больше 17 лет назад

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.

github
больше 3 лет назад

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.