Firebird and Suse

Since I helped Mandriva to do their packages for Firebird, I jumped and with Michal, we made things happen
Users of Opensuse 10.0,10.1,10.3 and future 11.0 but also SLE 10 can now just use the server:database repository  and get Firebird 2.0.4
As soon as the Firebird Project will publish Firebird 2.1.1, packages will be there too.

firebird2.0 security bug is now fixed in debian/gentoo

There is an grave security bug in firebird package 2.0 from debian and ubuntu
where an user can connect to the server with SYSDBA and NO password

The bug is now fixed in debian sid (unstable)

http://packages.debian.org/sid/firebird2.0-super
and here is the changelog

firebird2.0-super.init: stop exporting ISC_USER and ISC_PASSWORD.
Fixes a hole causing remote connections as user SYSDBA to succeed
without giving a password.
Closes: #481389 and CVE-2008-1880

Read more

1 55 56 57 58 59 84