PT-2026-33475 · Firebirdsql · Firebird
Published
2026-04-17
·
Updated
2026-04-17
·
CVE-2025-65104
CVSS v3.1
7.9
High
| AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L |
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firebird