<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>190833</bug_id>
          
          <creation_ts>2007-08-31 00:18 0000</creation_ts>
          <short_desc>dev-db/firebird &lt; 2.0.2 Multiple Vulnerabilities (CVE-2007-{466[456789],5246})</short_desc>
          <delta_ts>2007-10-07 11:18:04 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/26615/</bug_file_loc>
          <status_whiteboard>B3 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>mjf@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>drizzt@gentoo.org</cc>
    
    <cc>max.dittrich@t-online.de</cc>
    
    <cc>wltjr@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>mjf@gentoo.org</who>
            <bug_when>2007-08-31 00:18:15 0000</bug_when>
            <thetext>Some vulnerabilities have been reported in Firebird, where some have unknown impact and others can be exploited by malicious users to cause a DoS (Denial of Service).

1) An error exists in the processing of event registration requests. This can potentially be exploited by a client application connected via XNET to crash the Firebird server by registering several events in parallel.

2) An error exists in the processing of network packets. This can potentially be exploited to increase the CPU load to a high value and consume large amounts of memory by sending large network packets containing garbage data.

3) An unspecified error exists in the processing of Service API calls. This can be exploited to cause a DoS on the affected Firebird server.

4) An unspecified vulnerability with unknown impact exists in the processing of &quot;attach database&quot; and &quot;create database&quot; commands when the passed filename is larger than &quot;MAX_PATH_LEN&quot;.

The vulnerabilities are reported in versions prior to 2.0.2.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mjf@gentoo.org</who>
            <bug_when>2007-08-31 00:20:03 0000</bug_when>
            <thetext>Cc&apos;ing maintainers and setting whiteboard status.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-08-31 01:34:11 0000</bug_when>
            <thetext>Wasn&apos;t even aware of release. I will see about bumping asap. I was in the process of moving to opt. Guess I will pause on that for now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-08-31 04:23:25 0000</bug_when>
            <thetext>Ok, I have bumped the ebuild and it compiled and seems to be good to go. If others can test, and if no problems we can look to rush stabilize.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-09-08 21:42:37 0000</bug_when>
            <thetext>arches, please stabilise dev-db/firebird-2.0.2.12964.0</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2007-09-09 13:31:42 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-09-12 09:24:59 0000</bug_when>
            <thetext>*** Bug 192274 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-09-12 09:26:38 0000</bug_when>
            <thetext>Firebird 2.0.2 is Recalled
The Firebird 2.0.2 release has been recalled due to a significant regression that has shown up (Tracker Issue CORE-1434). Our sincere apologies for the inconvenience. A release candidate for v.2.0.3 will follow shortly.

http://tracker.firebirdsql.org/browse/CORE-1434

(2.0.3_rc1 is out, BTW).
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-09-12 19:59:00 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; Firebird 2.0.2 is Recalled

Yeah not sure what&apos;s going on with apps I love and have never had issues with. ASSP and Firebird :(

&gt; (2.0.3_rc1 is out, BTW).

Not really. It&apos;s a pre-release, and I can&apos;t download sources. :(

http://www.firebirdsql.org/index.php?op=files&amp;id=fb203_rc1

404


</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-09-13 08:45:48 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; Not really. It&apos;s a pre-release, and I can&apos;t download sources. :(
&gt; 
&gt; http://www.firebirdsql.org/index.php?op=files&amp;id=fb203_rc1

Works fine here.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-09-13 13:53:27 0000</bug_when>
            <thetext>(In reply to comment #9)
&gt;
&gt; Works fine here.

So you can download sources?

http://www.firebirdsql.org/download/prerelease/Firebird-2.0.3.12981-0.tar.bz2

404</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-13 14:09:08 0000</bug_when>
            <thetext>(In reply to comment #10)
&gt; So you can download sources?
&gt; http://www.firebirdsql.org/download/prerelease/Firebird-2.0.3.12981-0.tar.bz2
&gt; 404

The link is wrong, but this works:
http://www.firebirdsql.org/download/prerelease/source/Firebird-2.0.3.12981-0.tar.bz2

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-09-13 14:40:21 0000</bug_when>
            <thetext>ok, thanks, a URL is what I needed for ebuild :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-09-13 22:14:03 0000</bug_when>
            <thetext>Ok pre-release committed to tree. I didn&apos;t tag it as such atm. Should be moot since if upstream does another 2.0.3 release, the build number will have gone up :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-14 00:35:02 0000</bug_when>
            <thetext>Thanks William. Arches, please test and stabilize dev-db/firebird-2.0.3.12981.0.
Target keywords: &quot;amd64 x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2007-09-15 14:47:47 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2007-09-16 14:17:21 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-09-16 16:52:58 0000</bug_when>
            <thetext>If severity level stays that way, glsa voting is now open.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-23 17:18:37 0000</bug_when>
            <thetext>In case of a GLSA, there&apos;s also CVE-2007-4669 not covered by the Secunia advisory. You might want to review it, too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-09-24 16:30:30 0000</bug_when>
            <thetext>I tend to vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-09-25 09:38:58 0000</bug_when>
            <thetext>I tend to vote NO too, though the 4th &quot;unspecified issue&quot; with the MAX_PATH_LEN might imply code execution :/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-10-02 21:30:18 0000</bug_when>
            <thetext>I usually vote noglsa for unspecified vulnerabilities with unknown impact. Plus, the DoS vulnerabilities by opening several connections or sending large packets could happen all the time.

Perhaps, there is CVE-2007-4669, but i don&apos;t know if the logfile would provide much sensible information.

I vote no, and closing. Feel free to reopen if you disagree.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-10-02 21:43:31 0000</bug_when>
            <thetext>Just as further info, unless a user is doing something abnormal with logging sensitive stuff to the log file. Having access to it&apos;s contents is quite moot IMHO. It hardly reveals much if anything. Other than maybe if someone were beating on a db server trying to take it down. While viewing logs at the same time to see any signs of distress.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>