CVE Vulnerabilities

CVE-2008-1880

Published: May 12, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.

Affected Software

Name Vendor Start Version End Version
Linux Gentoo * *
Firebird2 Ubuntu dapper *
Firebird2 Ubuntu feisty *
Firebird2.0 Ubuntu gutsy *
Firebird2.0 Ubuntu hardy *
Firebird2.0 Ubuntu upstream *

References