allows passwordless SYSDBA login

Bug #232420 reported by Damyan Ivanov
264
Affects Status Importance Assigned to Milestone
firebird2.0 (Debian)
Fix Released
Unknown
firebird2.0 (Gentoo Linux)
Fix Released
Medium
firebird2.0 (Ubuntu)
Fix Released
High
Unassigned
Nominated for Dapper by r12056
Nominated for Hardy by r12056
Nominated for Intrepid by r12056
Nominated for Jaunty by r12056
Nominated for Karmic by r12056
Nominated for Lucid by r12056
firebird2.1 (Debian)
Fix Released
Unknown

Bug Description

Binary package hint: firebird2.0-super

See http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481389 and http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1880

The init.d script exports ISC_PASSWORD into the environment before starting fbguard. fbguard itself spawns fbserver process without cleaning environment.

fbserver uses ISC_PASSWORD from the environment when remote connection
does not supply a password. This makes it possible to connect remotely
as SYSDBA user without giving a password.

That last part is already fixed in upstream CVS HEAD, but backporting
the change is reported to be non-trivial.

All versions are affected

CVE References

Revision history for this message
Ralph Janke (txwikinger) wrote :

Confirmed and severity set according to upstream bug in Debian

Changed in firebird2.0:
importance: Undecided → High
status: New → Confirmed
Changed in firebird2.0:
status: Unknown → Fix Released
Revision history for this message
Popa Adrian Marius (mapopa) wrote :

here is the relevant patch that must be applied to the versions in gutsy/hardy

http://git.debian.org/?p=pkg-firebird/2.0.git;a=commitdiff;h=db15b5744dd70864062bea0cefc15dfc74c33b66

bug seems to be fixed in intreprid 2.0.3.12981.ds1-15 is just imported from debian and that version contains the fix

https://bugs.edge.launchpad.net/ubuntu/+source/firebird2.0/2.0.3.12981.ds1-15

Changed in firebird2.0:
status: Unknown → Fix Released
Changed in firebird2.1:
status: Unknown → Fix Released
r12056 (r12056)
Changed in firebird2.0 (Ubuntu):
assignee: nobody → Ubuntu Security Team (ubuntu-security)
Revision history for this message
Chris Johnston (cjohnston) wrote :

Removed assignee that was added by r12056.

The nominations may not be appropriate. Please investigate and fix as appropriate.

Changed in firebird2.0 (Ubuntu):
assignee: Ubuntu Security Team (ubuntu-security) → nobody
Changed in firebird2.0 (Gentoo Linux):
importance: Unknown → Medium
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This was fixed in 2.0.3.12981.ds1-14.

Changed in firebird2.0 (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.