Firebird
cpe:2.3:a:firebird:firebird:*:*:*:*:*:*:*, +1 more
- >= 3.0.0, < 3.0.14
- >= 4.0.0, < 4.0.7
- >= 5.0.0, < 5.0.4
A denial-of-service vulnerability has been identified in Firebird, an open-source relational database management system. This issue affects versions prior to 5.0.4, 4.0.7, and 3.0.14. The vulnerability arises when the server receives an 'op_crypt_key_callback' packet without prior authentication. In such cases, the 'port_server_crypt_callback' handler is not properly initialized, leading to a null pointer dereference and a server crash. An unauthenticated attacker who knows the server's IP and port can exploit this flaw to cause a crash.
Exploitation of this vulnerability leads to a null pointer dereference, causing the Firebird server to crash.
The vulnerability can be reproduced by sending an 'op_crypt_key_callback' packet to the server without prior authentication. This can be done using a script that establishes a connection to the server and sends the packet, which triggers the null pointer dereference and subsequent crash.
Users can upgrade to Firebird versions 5.0.4, 4.0.7, or 3.0.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.