Firebird
cpe:2.3:a:firebird:firebird:*:*:*:*:*:*:*, +1 more
- >= 3, < 6.0
- ~5.0
- ~4.0
- ~3.0
A buffer overflow vulnerability has been identified in Firebird database versions prior to 5.0.4, 4.0.7, and 3.0.14. The issue arises in the xdr_datum() function, which improperly validates the length of cstrings during the deserialization of slice packets. This lack of validation allows an unauthenticated attacker to send a crafted packet that exceeds the allocated buffer, leading to a potential server crash or other security issues.
Exploitation of this vulnerability can cause a server crash or other unspecified security impacts.
The vulnerability can be reproduced by running the Firebird server and using a Python script to send a maliciously crafted slice packet that exploits the buffer overflow issue.
Users can upgrade to Firebird versions 5.0.4, 4.0.7, or 3.0.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.