Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Ubuntu 14.04 LTS USN-3929-1 Moderate: Firebird Remote Threats

ubuntu
Calendar Grey April 2, 2019
Scroller Ubuntu
Numerous vulnerabilities in Firebird have been addressed for Ubuntu users. Ensure your systems are updated to protect against potential remote attacks.
Several security issues were fixed in Firebird.

Summary

Several security issues were fixed in Firebird.

Software Description:

- firebird2.5: A full-featured, open source SQL database derived from Borland InterBase 6.0

Details:

It was discovered that Firebird incorrectly handled certain malformed

packets. A remote attacker could possibly use this issue with a specially

crafted network packet to cause Firebird to crash, resulting in a denial of

service.

(CVE-2014-9323)

It was discovered that Firebird incorrectly handled certain UDF libraries.

A remote attacker could possibly use this issue to execute arbitrary code.

(CVE-2017-6369)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  firebird2.5-classic             2.5.2.26540.ds4-9ubuntu1.1
  firebird2.5-classic-common      2.5.2.26540.ds4-9ubuntu1.1
  firebird2.5-server-common       2.5.2.26540.ds4-9ubuntu1.1
  firebird2.5-super               2.5.2.26540.ds4-9ubuntu1.1
  firebird2.5-superclassic        2.5.2.26540.ds4-9ubuntu1.1
  libfbclient2                    2.5.2.26540.ds4-9ubuntu1.1
  libfbembed2.5                   2.5.2.26540.ds4-9ubuntu1.1
  libib-util                      2.5.2.26540.ds4-9ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

CVE-2014-9323, CVE-2017-6369

Severity
important
Lowest
Low
Medium
High
Critical

April 02, 2019

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.