Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27890

Опубликовано: 17 апр. 2026
Источник: debian
EPSS Низкий

Описание

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firebird4.0fixed4.0.7.3271.ds6-1package
firebird3.0fixed3.0.14.ds7-1package

Примечания

  • https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-6crx-4g37-7j49

EPSS

Процентиль: 38%
0.00465
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
4 месяца назад

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS3: 8.2
nvd
4 месяца назад

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS3: 8.2
fstec
4 месяца назад

Уязвимость системы управления базами данных Firebird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.2
redos
3 месяца назад

Уязвимость firebird

suse-cvrf
3 месяца назад

Security update for firebird

EPSS

Процентиль: 38%
0.00465
Низкий