Borland InterBase畸形报文远程栈溢出漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

BUGTRAQ ID: 29302 Borland InterBase是跨平台的高性能商业数据库。 Borland Interbase数据库在处理发送给默认TCP 3050端口的畸形报文时存在整数溢出漏洞,最终可能导致栈溢出,允许以系统权限执行任意指令。 Solaris版本中的漏洞代码段: /----------- inet_accept_connection+0x164: srl %o5, 0x10, %o7 inet_accept_connection+0x168: ld [%l0 + 0xcc], %l1 inet_accept_connection+0x16c: sth %o7, [%l1 + 8] inet_accept_connection+0x170: ba +0x3a0 <inet_accept_connection+0x510> inet_accept_connection+0x174: ld [%fp - 0x8c], %g2 inet_accept_connection+0x178: ld [%fp - 0x88], %g3 inet_accept_connection+0x17c: add %fp, -0x84, %g2 inet_accept_connection+0x180: st %g2, [%fp - 0x90] inet_accept_connection+0x184: ldsb [%g3], %g4 inet_accept_connection+0x188: st %g4, [%fp - 0xa0] inet_accept_connection+0x18c: ld [%fp - 0x88], %o5 inet_accept_connection+0x190: add %o5, 1, %o7 inet_accept_connection+0x194: st %o7, [%fp - 0x88] inet_accept_connection+0x198: ld [%fp - 0xa0], %o4 inet_accept_connection+0x19c: st %o4, [%fp - 0x304] inet_accept_connection+0x1a0: ld [%fp - 0x304], %l0...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息