Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firebird25-serverUpgrade firebird21-server | Dec 10, 2025 | Mar 6, 2013 |
| Gentoo Linux | — | Upgrade dev-db/firebird. | Oct 30, 2017 | Mar 15, 2013 |
| Suse | — | Upgrade firebird-superserverUpgrade libfbembed2-32bitUpgrade firebird-debuginfoUpgrade firebird-filesystemUpgrade firebird-docUpgrade libfbclient2-x86Upgrade libfbembed2Upgrade libfbclient2-debuginfo-x86Upgrade firebirdUpgrade libfbclient2-32bitUpgrade libfbclient2-debuginfoUpgrade libfbembed2-x86Upgrade firebird-devel-debuginfoUpgrade firebird-classic-debuginfoUpgrade libfbembed2-debuginfo-x86Upgrade libfbclient2-develUpgrade firebird-classicUpgrade libfbclient2Upgrade firebird-debugsourceUpgrade libfbembed2_5Upgrade libfbembed2-debuginfoUpgrade libfbembed-develUpgrade firebird-superserver-debuginfoUpgrade firebird-32bitUpgrade firebird-develUpgrade libfbclient2-debuginfo-32bitUpgrade libfbembed2-debuginfo-32bit | Feb 17, 2015 | Mar 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub