Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-41038

Опубликовано: 20 мар. 2024
Источник: debian
EPSS Низкий

Описание

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firebird3.0not-affectedpackage

Примечания

  • https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-6fv8-8rwr-9692

EPSS

Процентиль: 19%
0.0006
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.

CVSS3: 7.5
nvd
больше 1 года назад

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость системы управления базами данных Firebird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
redos
больше 1 года назад

Уязвимость firebird

EPSS

Процентиль: 19%
0.0006
Низкий