Overview
Description
Interbase is an open source database package that is distributed by Borland/Inprise. The server contains a compiled-in backdoor account with a known password. In the following interbase code, references are made about a LOCKSMITH user: |
Impact
This backdoor allows any local user or remote user able to access port 3050/tcp [gds_db] to manipulate any database object on the system. This includes the ability to install trapdoors or other trojan horse software in the form of stored procedures. In addition, if the database software is running with root (*NIX) or System (NT) privileges, then any file on the server's file system can be overwritten, possibly leading to execution of arbitrary commands as root or System. |
Solution
Install the patch being distributed to change the backdoor server account password. |
Block access to port 3050/tcp; this will not, however, prevent local users or users within a firewall's adminstrative boundary from accessing the backdoor account. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.borland.com/interbase/downloads/patches.html
- http://www.borland.com/interbase/
- http://community.borland.com/interbase/
- http://sourceforge.net/projects/interbase
- http://sourceforge.net/projects/firebird
- http://sourceforge.net/projects/firebirdashes
- http://firebird.sourceforge.net
- http://www.ibphoenix.com
- http://www.ibphoenix.com/sec1.html
- http://firebird.ibphoenix.com
- http://www.interbase2000.com
- http://sourceforge.net/cvs/?group_id=1962 [Borland Interbase]
- http://sourceforge.net/cvs/?group_id=9052 [FirebirdAshes]
Acknowledgements
This document was written by Jeffrey S Havrilla.
Other Information
CVE IDs: | CVE-2001-0008 |
CERT Advisory: | CA-2001-01 |
Severity Metric: | 10.94 |
Date Public: | 2001-01-09 |
Date First Published: | 2001-01-10 |
Date Last Updated: | 2001-01-11 16:01 UTC |
Document Revision: | 49 |