// For flags

CVE-2007-5243

Borland Interbase - 'jrd8_create_database()' Remote Buffer Overflow

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

16
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.

Múltiples desbordamientos de búfer basados en pila en Borland InterBase LI 8.0.0.53 hasta 8.1.0.253, y WI 5.1.1.680 hasta 8.1.0.257, permite a atacantes remotos ejecutar código de su elección mediante (1) una petición larga de anexión a servicio en el puerto TCP 3050 a las funciones (a) SVC_attach o (b) INET_connect, (2) una petición larga de creación en el puerto TCP 3050 a las funciones (c) isc_create_database o (d) jrd8_create_database, (3) una petición de anexión larga en el puerto TCP 3050 a las funciones (e) isc_attach_database o (f) PWD_db_aliased, o vectores no especificados que involucran a las funciones (4) jrd8_attach_database o (5) expand_filename2.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-10-03 First Exploit
  • 2007-10-06 CVE Reserved
  • 2007-10-06 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (30)
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
li_8.0.0.53
Search vendor "Borland Software" for product "Interbase" and version "li_8.0.0.53"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
li_8.0.0.54
Search vendor "Borland Software" for product "Interbase" and version "li_8.0.0.54"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
li_8.0.0.253
Search vendor "Borland Software" for product "Interbase" and version "li_8.0.0.253"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-o6.0.1.6
Search vendor "Borland Software" for product "Interbase" and version "wi-o6.0.1.6"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-o6.0.2.0
Search vendor "Borland Software" for product "Interbase" and version "wi-o6.0.2.0"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v5.1.1.680
Search vendor "Borland Software" for product "Interbase" and version "wi-v5.1.1.680"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v5.5.0.742
Search vendor "Borland Software" for product "Interbase" and version "wi-v5.5.0.742"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v6.0.0.627
Search vendor "Borland Software" for product "Interbase" and version "wi-v6.0.0.627"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v6.0.1.0
Search vendor "Borland Software" for product "Interbase" and version "wi-v6.0.1.0"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v6.0.1.6
Search vendor "Borland Software" for product "Interbase" and version "wi-v6.0.1.6"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v6.5.0.28
Search vendor "Borland Software" for product "Interbase" and version "wi-v6.5.0.28"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v7.0.1.1
Search vendor "Borland Software" for product "Interbase" and version "wi-v7.0.1.1"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v7.5.0.129
Search vendor "Borland Software" for product "Interbase" and version "wi-v7.5.0.129"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v7.5.1.80
Search vendor "Borland Software" for product "Interbase" and version "wi-v7.5.1.80"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi-v8.0.0.123
Search vendor "Borland Software" for product "Interbase" and version "wi-v8.0.0.123"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi_5.1.1.680
Search vendor "Borland Software" for product "Interbase" and version "wi_5.1.1.680"
-
Affected
Borland Software
Search vendor "Borland Software"
Interbase
Search vendor "Borland Software" for product "Interbase"
wi_8.1.0.257
Search vendor "Borland Software" for product "Interbase" and version "wi_8.1.0.257"
-
Affected