Remote Code Execution via 'system' Entrypoint in Firebird UDF Subsystem

Remote Code Execution via 'system' Entrypoint in Firebird UDF Subsystem

CVE-2017-6369 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.

Learn more about our User Device Pen Test.