Upstream information

CVE-2013-2492 at MITRE

Description

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 808268 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Desktop 12 GA libfbembed2_5
SUSE Linux Enterprise Desktop 12 SP1
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA libfbembed2_5
SUSE Linux Enterprise Desktop 12 SP2
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA libfbembed2_5
SUSE Linux Enterprise Desktop 12 SP3
  • libfbembed2_5 >= 2.5.2.26539-15.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA libfbembed2_5
SUSE Linux Enterprise Software Development Kit 12
  • firebird-devel >= 2.5.2.26539-13.42
  • libfbembed-devel >= 2.5.2.26539-13.42
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA firebird-devel
SUSE Linux Enterprise Software Development Kit 12 SP1
  • firebird-devel >= 2.5.2.26539-13.42
  • libfbembed-devel >= 2.5.2.26539-13.42
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA firebird-devel
SUSE Linux Enterprise Software Development Kit 12 SP2
  • libfbembed-devel >= 2.5.2.26539-13.42
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA libfbembed-devel
SUSE Linux Enterprise Software Development Kit 12 SP3
  • libfbembed-devel >= 2.5.2.26539-15.1
  • libfbembed2_5 >= 2.5.2.26539-15.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP3 GA libfbembed-devel
SUSE Linux Enterprise Workstation Extension 12
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 GA libfbembed2_5
SUSE Linux Enterprise Workstation Extension 12 SP1
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 SP1 GA libfbembed2_5
SUSE Linux Enterprise Workstation Extension 12 SP2
  • libfbembed2_5 >= 2.5.2.26539-13.42
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 SP2 GA libfbembed2_5
SUSE Linux Enterprise Workstation Extension 12 SP3
  • libfbembed2_5 >= 2.5.2.26539-15.1
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 SP3 GA libfbembed2_5
openSUSE Leap 42.1
  • libfbembed2_5 >= 2.5.4.26856-5.4
Patchnames:
openSUSE Leap 42.1 GA libfbembed2_5
openSUSE Leap 42.2
  • libfbembed2_5 >= 2.5.6.27020-8.1
Patchnames:
openSUSE Leap 42.2 GA libfbembed2_5
openSUSE Tumbleweed
  • firebird >= 3.0.1.32609-1.3
  • firebird-doc >= 3.0.1.32609-1.3
  • firebird-examples >= 3.0.1.32609-1.3
  • firebird-server >= 3.0.1.32609-1.3
  • firebird-utils >= 3.0.1.32609-1.3
  • libfbclient-devel >= 3.0.1.32609-1.3
  • libfbclient2 >= 3.0.1.32609-1.3
  • libfbclient2-32bit >= 3.0.1.32609-1.3
  • libib_util >= 3.0.1.32609-1.3
  • libib_util-32bit >= 3.0.1.32609-1.3
  • libib_util-devel >= 3.0.1.32609-1.3
Patchnames:
openSUSE Tumbleweed GA firebird