top of page
perceptive_background_267k.jpg

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the le…

Published:

16 april 2026 om 22:00:00

Alert date:

17 april 2026 om 21:03:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage

A denial of service vulnerability exists in Firebird open-source database management system versions prior to 5.0.4, 4.0.7 and 3.0.14. The sdl_desc() function fails to validate the length of decoded SDL descriptors from slice packets. When a zero-length descriptor is processed, it causes a division by zero error during slice item calculation. Unauthenticated attackers can exploit this flaw by sending specially crafted slice packets to crash the database server. The vulnerability has been patched in the latest versions across all affected branches.

Technical details

Mitigation steps:

Affected products:

Firebird

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page