Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firebird21-serverUpgrade firebird25-server | Dec 10, 2025 | Mar 6, 2013 |
| Gentoo Linux | — | Upgrade dev-db/firebird. | Oct 30, 2017 | Mar 15, 2013 |
| Suse | — | Upgrade libfbembed2-debuginfoUpgrade libfbembed-develUpgrade firebird-superserver-debuginfoUpgrade libfbclient2-develUpgrade libfbembed2-debuginfo-32bitUpgrade libfbembed2-debuginfo-x86Upgrade firebird-debugsourceUpgrade firebird-classicUpgrade firebird-develUpgrade firebird-32bitUpgrade libfbclient2-debuginfo-32bitUpgrade libfbclient2Upgrade libfbembed2_5Upgrade libfbclient2-debuginfo-x86Upgrade firebird-devel-debuginfoUpgrade firebird-superserverUpgrade firebird-docUpgrade libfbclient2-x86Upgrade libfbembed2-32bitUpgrade libfbclient2-32bitUpgrade firebirdUpgrade libfbembed2Upgrade firebird-filesystemUpgrade libfbclient2-debuginfoUpgrade libfbembed2-x86Upgrade firebird-classic-debuginfoUpgrade firebird-debuginfo | Feb 17, 2015 | Mar 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub