CVE-2017-6369Missing Authorization in Firebird

Severity
8.8HIGHNVD
OSV5.0
EPSS
8.9%
top 7.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Latest updateMay 13

Description

Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDfirebirdsql/firebird2.5.02.5.7+1

🔴Vulnerability Details

4
GHSA
GHSA-vf42-c4fw-rcm3: Insufficient checks in the UDF subsystem in Firebird 22022-05-13
OSV
firebird2.5 vulnerabilities2019-04-02
OSV
CVE-2017-6369: Insufficient checks in the UDF subsystem in Firebird 22017-03-24
CVEList
CVE-2017-6369: Insufficient checks in the UDF subsystem in Firebird 22017-03-24

📋Vendor Advisories

3
Ubuntu
Firebird vulnerability2021-03-15
Ubuntu
Firebird vulnerabilities2019-04-02
Debian
CVE-2017-6369: firebird3.0 - Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0....2017

💬Community

3
Bugzilla
CVE-2017-6369 firebird: Access to undesired external modules during 'Restrict' configuration mode [epel-all]2017-02-21
Bugzilla
CVE-2017-6369 firebird: Access to undesired external modules during 'Restrict' configuration mode2017-02-21
Bugzilla
CVE-2017-6369 firebird: Access to undesired external modules during 'Restrict' configuration mode [fedora-all]2017-02-21
CVE-2017-6369 — Missing Authorization in Firebird | cvebase