CVE-2008-0387

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
29/01/2008
Last modified:
09/04/2025

Description

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* 1.0.3 (including)
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* 1.5 (including) 1.5.6 (excluding)
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.4 (excluding)
cpe:2.3:a:firebirdsql:firebird:2.1.0:*:*:*:*:*:*:*