CVE-2007-5243 (CNNVD-200710-118)
中文标题:
Borland InterBase和Firebird数据库多个远程栈缓冲区溢出漏洞
英文标题:
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1...
漏洞描述
中文描述:
Borland InterBase跨平台的高性能商业数据库。 Borland InterBase LI在处理用户数据时存在多个缓冲区溢出漏洞,远程攻击者可能利用这些漏洞控制服务器。 Borland InterBase的多个函数没有验证用户数据便将其拷贝到了栈缓冲区,如果远程攻击者在TCP 3050端口向SVC_attach或INET_connect函数发送了超长的service attach请求,或向isc_create_database或jrd8_create_database函数发送了超长的create请求,或向open_marker_file(仅限UNIX平台)、isc_attach_database或PWD_db_aliased函数发送了超长的attach请求,或向jrd8_attach_database或expand_filename2函数发送了超长请求的话,就可以触发多个栈溢出,导致执行任意指令。
英文描述:
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| borland_software | interbase | li_8.0.0.53 | - | - |
cpe:2.3:a:borland_software:interbase:li_8.0.0.53:*:*:*:*:*:*:*
|
| borland_software | interbase | li_8.0.0.54 | - | - |
cpe:2.3:a:borland_software:interbase:li_8.0.0.54:*:*:*:*:*:*:*
|
| borland_software | interbase | li_8.0.0.253 | - | - |
cpe:2.3:a:borland_software:interbase:li_8.0.0.253:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-o6.0.1.6 | - | - |
cpe:2.3:a:borland_software:interbase:wi-o6.0.1.6:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-o6.0.2.0 | - | - |
cpe:2.3:a:borland_software:interbase:wi-o6.0.2.0:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v5.1.1.680 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v5.1.1.680:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v5.5.0.742 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v5.5.0.742:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v6.0.0.627 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v6.0.0.627:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v6.0.1.0 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v6.0.1.0:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v6.0.1.6 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v6.0.1.6:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v6.5.0.28 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v6.5.0.28:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v7.0.1.1 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v7.0.1.1:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v7.5.0.129 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v7.5.0.129:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v7.5.1.80 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v7.5.1.80:*:*:*:*:*:*:*
|
| borland_software | interbase | wi-v8.0.0.123 | - | - |
cpe:2.3:a:borland_software:interbase:wi-v8.0.0.123:*:*:*:*:*:*:*
|
| borland_software | interbase | wi_5.1.1.680 | - | - |
cpe:2.3:a:borland_software:interbase:wi_5.1.1.680:*:*:*:*:*:*:*
|
| borland_software | interbase | wi_8.1.0.257 | - | - |
cpe:2.3:a:borland_software:interbase:wi_8.1.0.257:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
CVSS评分详情
AV:N/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-5243 |
2025-11-11 15:17:56 | 2025-11-11 07:32:47 |
| NVD | nvd_CVE-2007-5243 |
2025-11-11 14:52:12 | 2025-11-11 07:41:33 |
| CNNVD | cnnvd_CNNVD-200710-118 |
2025-11-11 15:08:58 | 2025-11-11 07:49:21 |
| EXPLOITDB | exploitdb_EDB-10020 |
2025-11-11 15:05:26 | 2025-11-11 08:00:24 |
| EXPLOITDB | exploitdb_EDB-10021 |
2025-11-11 15:05:26 | 2025-11-11 08:00:24 |
| EXPLOITDB | exploitdb_EDB-16420 |
2025-11-11 15:05:55 | 2025-11-11 08:11:00 |
| EXPLOITDB | exploitdb_EDB-16432 |
2025-11-11 15:05:55 | 2025-11-11 08:11:00 |
| EXPLOITDB | exploitdb_EDB-16437 |
2025-11-11 15:05:55 | 2025-11-11 08:11:00 |
| EXPLOITDB | exploitdb_EDB-16440 |
2025-11-11 15:05:55 | 2025-11-11 08:11:00 |
| EXPLOITDB | exploitdb_EDB-16447 |
2025-11-11 15:05:55 | 2025-11-11 08:11:01 |
| EXPLOITDB | exploitdb_EDB-16449 |
2025-11-11 15:05:55 | 2025-11-11 08:11:01 |
| EXPLOITDB | exploitdb_EDB-16839 |
2025-11-11 15:05:26 | 2025-11-11 08:11:15 |
| EXPLOITDB | exploitdb_EDB-16843 |
2025-11-11 15:05:26 | 2025-11-11 08:11:15 |
| EXPLOITDB | exploitdb_EDB-16844 |
2025-11-11 15:05:26 | 2025-11-11 08:11:15 |
| EXPLOITDB | exploitdb_EDB-9954 |
2025-11-11 15:05:26 | 2025-11-11 09:07:04 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 41 -> 43
查看详细变更
- references_count: 39 -> 41
查看详细变更
- references_count: 37 -> 39
查看详细变更
- references_count: 35 -> 37
查看详细变更
- references_count: 33 -> 35
查看详细变更
- references_count: 31 -> 33
查看详细变更
- references_count: 29 -> 31
- tags_count: 7 -> 8
查看详细变更
- references_count: 27 -> 29
查看详细变更
- references_count: 25 -> 27
查看详细变更
- references_count: 23 -> 25
- tags_count: 5 -> 7
查看详细变更
- references_count: 21 -> 23
- tags_count: 4 -> 5
查看详细变更
- references_count: 18 -> 21
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200710-118
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 17
- data_sources: ['cve'] -> ['cve', 'nvd']