firebird2.0 security bug is now fixed in debian/gentoo

There is an grave security bug in firebird package 2.0 from debian and ubuntu
where an user can connect to the server with SYSDBA and NO password

The bug is now fixed in debian sid (unstable)

http://packages.debian.org/sid/firebird2.0-super
and here is the changelog

firebird2.0-super.init: stop exporting ISC_USER and ISC_PASSWORD.
Fixes a hole causing remote connections as user SYSDBA to succeed
without giving a password.
Closes: #481389 and CVE-2008-1880

Firebird security bug fixed in gentoo linux

Firebird allows remote connections to the administrative account without verifying credentials.

Firebird 2.04 is out

The members of the Firebird Project announce the release of Firebird 2.0.4, a point release with fixes for several Nbackup problems. Forced writes on Linux will work with this version. Summary here, downloads here.

Kits are starting to come through to some European mirrors. As usual, we ask for your patience if they are slow reaching your local mirror.

Firebird 2.1 is Released

The members of the Firebird Project team are proud to announce the release of Firebird 2.1, a full release containing many sought-after new features including database monitoring, global temporary tables, database triggers and dozens of new internal functions.

This release includes kits for 64-bit Windows and all MacOSX environments and constitutes our largest-ever platform coverage. Enjoy!         Details Downloads

Firebird Project Releases Firebird 2.5 Zeta 2

“The Firebird Project today officially releases the much-anticipated version 2.5 Zeta 2 of its open source Firebird relational database software.

The 2.5 release has many interesting new features that you can play with, like database triggers, temporary and monitoring tables, common table expressions, recursive queries and dozens of new inbuilt functions. We encourage you to see what you can achieve with these new features and let us know about any deficiency.

Windows ,MacOSX ,Linux kits fir 32-bit and 64-bit platforms are ready to download now You are invited to test it furiously and report your experiences (good or bad) back to the firebird-devel list.

It brings with it a large collection of long-awaited enhancements that  significantly improve performance, security and support for international languages and realise some desirable new SQL language features. Under the surface, it also provides a much more robust code platform from which the re-architecting planned for Firebird 3.0 is proceeding.

The Firebird project roadmap for 2008 is now available.”

FB 2.5 first Alpha is coming…

Posted in Firebird-Devel, by Dmitry Yemanov:

All,

The codebase will be tagged for Alpha 1 as soon as v2.0.4 RC1 and v2.1 Final are released. This means 10-15 days available to finalize the ODS changes and complete the major refactoring and synchronization efforts.

We expect only one Alpha version to be released. The next one will be Beta 1 which should be feature complete. No new ODS changes are allowed for Beta, unless some bugs would require fixing.

Besides the features already scheduled for v2.5 in the tracker, we have two features that the Foundation TTG (technical task group) has agreed to consider for this release during the Alpha stage: (1) tracing facility by Nickolay and (2) cross-database EXECUTE STATEMENT implementation by Vlad. They will be reviewed and discussed here soon, with an intention to be committed into the codebase before Beta.

Unfortunately, provided that the “external stored procedures” feature has major issues we still cannot resolve in the agreement (e.g. security and external engine API), it doesn’t seem to fit the v2.5 timeframe and is going to be postponed. Sad but true.

Comments anyone? We still have a bit of time to resolve your questions and adjust the release plan, if required. Just don’t forget that we want v2.5 to be a quick release and we’re already one month behind the schedule…

Dmitry

1 16 17 18 19 20 27