There is an grave security bug in firebird package 2.0 from debian and ubuntu
where an user can connect to the server with SYSDBA and NO password
The bug is now fixed in debian sid (unstable)
An quick fix if you have an firebird2.0 debian/ubuntu package is to delete these lines in the /etc/init.d/firebird2.0-super
[ -r “$DBAPasswordFile” ] && . “$DBAPasswordFile”
Or get the git version of the package and copy the init script
$sudo cp 2.0/debian/firebird2.0-super.init /etc/init.d/firebird2.0-super
You can test and install it on debian experimental
ps: soon there will be an firebird2.1 package for ubuntu created (it wasn’t possible to include it in this short period of time after release)
This Debian security advisory is a bit unusual. While it’s normally
our strict policy to backport security bugfixes to older releases, this
turned out to be infeasible for Firebird 1.5 due to large infrastructural
changes necessary to fix these issues. As a consequence security support
for Firebird 1.5 is hereby discontinued, leaving two options to
administrators running a Firebird database:
I. Administrators running Firebird in a completely internal setup with
trusted users could leave it unchanged.
II. Everyone else should upgrade to the firebird2.0 packages available at
Version 220.127.116.1181.ds1-6~bpo40+1 fixes all known issues.
Please refer to the general backports.org documentation to add the
packages to your package management configuration:
These packages are backported to run with Debian stable. Since
firebird2.0 is not a drop-in replacement for firebird2 (which
is the source package name for the Firebird 1.5 packages)
these updates are not released through security.debian.org.
Potential future security problems affecting Debian stable will be
released through backports.org as well.
Arrangements have been made to ensure that Firebird in the upcoming
Debian 5.0 release will be supportable with regular backported
security bugfixes again.
firebird2.0 package is now included in debian etch backports (stable)
for using the etch stable backports read this reference
firebird 2.0 package is also included in testing