Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Производитель ПО
Наименование ПО
firebird2.5-classic
(any)
firebird2.5-classic-common
(any)
firebird2.5-classic-dbg
(any)
firebird2.5-common
(any)
firebird2.5-common-doc
(any)
firebird2.5-doc
(any)
firebird2.5-examples
(any)
firebird2.5-server-common
(any)
firebird2.5-super
(any)
firebird2.5-superclassic
(any)
firebird2.5-super-dbg
(any)
firebird-dev
(any)
libfbclient2
(any)
libfbclient2-dbg
(any)
libfbembed2.5
(any)
libib-util
(any)
Описание
Джордж Носивич обнаружил, что firebird2.5, система реляционных баз
данных, неправильно выполняет проверку определяемых пользователем функций (UDF),
позволяя удалённым аутентифицированным пользователям выполнять произвольный
код на сервере firebird.
В стабильном выпуске (jessie) эта проблема была исправлена в
версии 2.5.3.26778.ds4-5+deb8u1.
Рекомендуется обновить пакеты firebird2.5.
данных, неправильно выполняет проверку определяемых пользователем функций (UDF),
позволяя удалённым аутентифицированным пользователям выполнять произвольный
код на сервере firebird.
В стабильном выпуске (jessie) эта проблема была исправлена в
версии 2.5.3.26778.ds4-5+deb8u1.
Рекомендуется обновить пакеты firebird2.5.
Как исправить
Проблема может быть решена обновлением операционной системыдо следующих версий пакетов в зависимости от архитектуры:
Debian GNU/Linux 8:
noarch:
firebird-dev - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-classic - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-classic-common - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-classic-dbg - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-common - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-common-doc - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-doc - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-examples - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-server-common - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-super - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-super-dbg - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-superclassic - 2.5.3.26778.ds4-5+deb8u1
libfbclient2 - 2.5.3.26778.ds4-5+deb8u1
libfbclient2-dbg - 2.5.3.26778.ds4-5+deb8u1
libfbembed2.5 - 2.5.3.26778.ds4-5+deb8u1
libib-util - 2.5.3.26778.ds4-5+deb8u1
Debian GNU/Linux 8:
noarch:
firebird-dev - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-classic - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-classic-common - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-classic-dbg - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-common - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-common-doc - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-doc - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-examples - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-server-common - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-super - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-super-dbg - 2.5.3.26778.ds4-5+deb8u1
firebird2.5-superclassic - 2.5.3.26778.ds4-5+deb8u1
libfbclient2 - 2.5.3.26778.ds4-5+deb8u1
libfbclient2-dbg - 2.5.3.26778.ds4-5+deb8u1
libfbembed2.5 - 2.5.3.26778.ds4-5+deb8u1
libib-util - 2.5.3.26778.ds4-5+deb8u1
Ссылки
http://www.debian.org/security/dsa-3824/
Источник: CVE
Наименование: CVE-2017-6369
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6369
Источник: CVE
Наименование: CVE-2017-6369
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6369