Firebird Documentation Index → Firebird 2.1 Release Notes → Security → Other Security Improvements |
(V.2.1) When the server is configured "DatabaseAccess = None",
isc_service_query()
would return the full database file path and name. It has been
corrected to return the database alias—one more argument in favour of making the use of database aliases
standard practice!
This was a minor security vulnerability. Regular users are now blocked from retrieving the server log using the Services API. Requests are explicitly checked to ensure that the authenticated user is SYSDBA.
Firebird Documentation Index → Firebird 2.1 Release Notes → Security → Other Security Improvements |