CVE-2008-1880
Published: 12 May 2008
The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.
Priority
Status
Package | Release | Status |
---|---|---|
firebird2 Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
feisty |
Ignored
(end of life, was needs-triage)
|
|
gutsy |
Does not exist
|
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
firebird2.0 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
feisty |
Does not exist
|
|
gutsy |
Ignored
(end of life, was needs-triage)
|
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Not vulnerable
(2.0.4.13130-1.ds1-3)
|
|
jaunty |
Not vulnerable
(2.0.4.13130-1.ds1-5ubuntu1)
|
|
karmic |
Not vulnerable
(2.0.5.13206-0.ds2-4)
|
|
upstream |
Released
(2.0.3.12981)
|