LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How would you rate the importance of default settings in security?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: May 16th, 2008
Linux Security Week: May 13th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Debian: New Firebird packages fix several vulnerabilities Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Debian Multiple security problems have been discovered in the Firebird database, which may lead to the execution of arbitrary code or denial of service.
- ------------------------------------------------------------------------
Debian Security Advisory DSA-1529-1                  security@debian.org
http://www.debian.org/security/                       Moritz Muehlenhoff
March 24, 2008                        http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : firebird2
Vulnerability  : several
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2008-0387 CVE-2008-0467 CVE-2006-7211 CVE-2007-4664
                 CVE-2007-4665 CVE-2007-4666 CVE-2007-4667 CVE-2007-4668
                 CVE-2007-4669 CVE-2007-3527 CVE-2007-3181 CVE-2007-2606
                 CVE-2006-7212 CVE-2006-7213 CVE-2006-7214
Debian Bug(s)  : 362001 432753 444976 441405 460048 463596

Multiple security problems have been discovered in the Firebird database,
which may lead to the execution of arbitrary code or denial of service.

This Debian security advisory is a bit unusual. While it's normally 
our strict policy to backport security bugfixes to older releases, this
turned out to be infeasible for Firebird 1.5 due to large infrastructural
changes necessary to fix these issues. As a consequence security support
for Firebird 1.5 is hereby discontinued, leaving two options to
administrators running a Firebird database:

I.  Administrators running Firebird in a completely internal setup with
    trusted users could leave it unchanged.

II. Everyone else should upgrade to the firebird2.0 packages available at 
    http://www.backports.org/backports.org/pool/main/f/firebird2.0/

    Version 2.0.3.12981.ds1-6~bpo40+1 fixes all known issues.

    Please refer to the general backports.org documentation to add the
    packages to your package management configuration:
    http://www.backports.org/dokuwiki/doku.php?id=instructions

    These packages are backported to run with Debian stable. Since
    firebird2.0 is not a drop-in replacement for firebird2 (which
    is the source package name for the Firebird 1.5 packages)
    these updates are not released through security.debian.org.
    Potential future security problems affecting Debian stable will be
    released through backports.org as well.

    Arrangements have been made to ensure that Firebird in the upcoming
    Debian 5.0 release will be supportable with regular backported
    security bugfixes again.

For a more detailed descriptions of the security problems, please refer
to the entries in the Debian Bug Tracking System referenced above and
the following URLs:

http://www.firebirdsql.org/rlsnotes/Firebird-2.0-ReleaseNotes.pdf
http://www.firebirdsql.org/rlsnotes/Firebird-2.0.1-ReleaseNotes.pdf
http://www.firebirdsql.org/rlsnotes/Firebird-2.0.2-ReleaseNotes.pdf

- ---------------------------------------------------------------------------------
Mailing list: debian-security-announce@lists.debian.org
 
< Prev   Next >
    
Partner:

 

Latest Features
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Meet the Anti-Nmap: PSAD
Open Source Tool of February: Nmap!
HowTo: Secure your Ubuntu Apache Web Server
SSH: Best Practices
Yesterday's Edition
Strong passwords no panacea as SSH Brute-Force Attacks Rise
Tools circulate that crack Debian, Ubuntu keys

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.