PT-2026-33475 · Firebird · Firebird Client Library

Published

2026-04-17

·

Updated

2026-04-25

·

CVE-2025-65104

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Firebird client library version FB3
Description The FB3 client library places incorrect data length values into XSQLDA fields when communicating with Firebird servers version FB4 or higher, which leads to an information leak.
Recommendations Upgrade to the FB4 client or higher.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-65104
OESA-2026-2013
OESA-2026-2014
OESA-2026-2015
OESA-2026-2016
OESA-2026-2017

Affected Products

Firebird Client Library