Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firebird21-serverUpgrade firebird25-server | Dec 10, 2025 | Mar 6, 2013 |
| Gentoo Linux | — | Upgrade dev-db/firebird. | Oct 30, 2017 | Mar 15, 2013 |
| Suse | — | Upgrade libfbclient2Upgrade firebird-superserver-debuginfoUpgrade firebird-classicUpgrade libfbembed2-debuginfo-x86Upgrade libfbembed2-debuginfoUpgrade firebird-debugsourceUpgrade libfbclient2-develUpgrade libfbembed2_5Upgrade libfbclient2-debuginfo-32bitUpgrade libfbembed2-debuginfo-32bitUpgrade libfbembed-develUpgrade firebird-develUpgrade firebird-32bitUpgrade firebird-docUpgrade firebird-superserverUpgrade libfbembed2-32bitUpgrade firebirdUpgrade firebird-debuginfoUpgrade firebird-devel-debuginfoUpgrade libfbclient2-32bitUpgrade libfbclient2-x86Upgrade libfbclient2-debuginfoUpgrade firebird-filesystemUpgrade libfbembed2-x86Upgrade firebird-classic-debuginfoUpgrade libfbembed2Upgrade libfbclient2-debuginfo-x86 | Feb 17, 2015 | Mar 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub