fb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of service (blocked query processing) by locking semaphores.
Link | Tags |
---|---|
http://www.firebirdsql.org/rlsnotes/Firebird-2.0-ReleaseNotes.pdf | patch |
http://www.securityfocus.com/bid/28474 | vdb entry |
http://secunia.com/advisories/29501 | third party advisory |
http://www.debian.org/security/2008/dsa-1529 | vendor advisory |