Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 571824 (CVE-2016-1569) - dev-db/firebird: authenticated remote crash by gbak invocation
Summary: dev-db/firebird: authenticated remote crash by gbak invocation
Status: RESOLVED FIXED
Alias: CVE-2016-1569
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-14 09:47 UTC by Agostino Sarubbo
Modified: 2016-09-30 15:21 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-01-14 09:47:24 UTC
From ${URL} :

Firebird 2.5.5 can be crashed remotely by authenticated clients by invoking 
gbak via the service manager using invalid command line switch.

This is harmless for the -classic flavour where the server process serves only 
that particular connection, but is at least a DoS for -super and -superclassic 
where the crashed process serves multiple connections.

Upstream issue:

http://tracker.firebirdsql.org/browse/CORE-5068

CVE request:

http://seclists.org/oss-sec/2016/q1/57


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 William L. Thomson Jr. 2016-03-01 21:36:47 UTC
Have you read this CVE at all? This looks to be once again 100% windows specific. I am also not seeing how this is a remote exploit. Given gbak is a command line utility.
Comment 2 William L. Thomson Jr. 2016-03-01 21:42:19 UTC
This also looks to be a issues that was introduce on a version of Firebird not even in tree, per CVE

"
Vlad Khorsun added a comment - 06/Jan/16 07:42 AM
The bug was introduced in build 26948 by my commit 

Revision: 62434 
Author: hvlad 
Date: 27 October 2015 г. 13:20:18 
Message: 
Backport feature CORE-1999 : TimeStamp in the every line output gbak.exe utility 

It was sad typo when backporting
"
Comment 3 William L. Thomson Jr. 2016-03-01 21:48:58 UTC
Close as invalid as this version is not in portage. I have it in my overlay but I have already moved onto Firebird 3.0 which does not seem effected by this.
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-09-30 15:21:34 UTC
Package not in stable, no security tracking