Debian Security Advisory

DSA-2648-1 firebird2.5 -- several vulnerabilities

Date Reported:
15 Mar 2013
Affected Packages:
firebird2.5
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-5529, CVE-2013-2492.
More information:

A buffer overflow was discovered in the Firebird database server, which could result in the execution of arbitrary code. In addition, a denial of service vulnerability was discovered in the TraceManager.

For the stable distribution (squeeze), these problems have been fixed in version 2.5.0.26054~ReleaseCandidate3.ds2-1+squeeze1.

For the testing distribution (wheezy), these problems will be fixed soon.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your firebird2.5 packages.