PT-2025-33492 · Firebird+3 · Firebird+3

Published

2025-08-15

·

Updated

2025-11-17

·

CVE-2025-54989

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Firebird versions prior to 3.0.13 Firebird versions prior to 4.0.6 Firebird versions prior to 5.0.3
Description: Firebird is a relational database. A NULL pointer dereference denial-of-service vulnerability exists in Firebird when parsing XDR messages from a client. This flaw leads to a NULL pointer dereference and denial-of-service condition.
Recommendations: Update Firebird to version 3.0.13 or later. Update Firebird to version 4.0.6 or later. Update Firebird to version 5.0.3 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11799
BDU:2025-11068
CVE-2025-54989
DLA-4282-1
DSA-5992-1
GHSA-7QP6-HQXJ-PJJP
SUSE-SU-2025:02991-1
ZDI-25-859

Affected Products

Alt Linux
Debian
Firebird
Red Os