Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firebird21-serverUpgrade firebird25-server | Dec 10, 2025 | Mar 6, 2013 |
| Gentoo Linux | — | Upgrade dev-db/firebird. | Oct 30, 2017 | Mar 15, 2013 |
| Suse | — | Upgrade libfbembed2-debuginfoUpgrade firebird-develUpgrade firebird-32bitUpgrade libfbembed2-debuginfo-32bitUpgrade libfbembed-develUpgrade firebird-classicUpgrade libfbclient2-develUpgrade libfbembed2_5Upgrade libfbclient2Upgrade firebird-superserver-debuginfoUpgrade libfbclient2-debuginfo-32bitUpgrade libfbembed2-debuginfo-x86Upgrade firebird-debugsourceUpgrade firebird-devel-debuginfoUpgrade libfbclient2-32bitUpgrade libfbclient2-debuginfo-x86Upgrade libfbembed2Upgrade libfbclient2-x86Upgrade libfbclient2-debuginfoUpgrade firebird-docUpgrade firebird-classic-debuginfoUpgrade libfbembed2-32bitUpgrade firebird-superserverUpgrade libfbembed2-x86Upgrade firebirdUpgrade firebird-filesystemUpgrade firebird-debuginfo | Feb 17, 2015 | Mar 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub