Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firebird25-serverUpgrade firebird21-server | Dec 10, 2025 | Mar 6, 2013 |
| Gentoo Linux | — | Upgrade dev-db/firebird. | Oct 30, 2017 | Mar 15, 2013 |
| Suse | — | Upgrade firebird-superserverUpgrade libfbembed2-32bitUpgrade libfbembed2Upgrade libfbembed2-x86Upgrade libfbclient2-debuginfoUpgrade firebird-docUpgrade libfbclient2-32bitUpgrade firebirdUpgrade libfbclient2-x86Upgrade firebird-debuginfoUpgrade libfbclient2-debuginfo-x86Upgrade firebird-classic-debuginfoUpgrade firebird-devel-debuginfoUpgrade firebird-filesystemUpgrade libfbclient2-debuginfo-32bitUpgrade firebird-debugsourceUpgrade libfbembed2_5Upgrade libfbclient2Upgrade libfbembed2-debuginfo-32bitUpgrade firebird-classicUpgrade firebird-superserver-debuginfoUpgrade firebird-develUpgrade libfbembed2-debuginfoUpgrade libfbclient2-develUpgrade libfbembed-develUpgrade libfbembed2-debuginfo-x86Upgrade firebird-32bit | Feb 17, 2015 | Mar 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub