Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities. The problems are fixed in the current 1.5.3 version of the Firebird binary distribution.
Publication date: Wed, 15 Mar 2006 23:06:00 +0000