PT-2026-33480 · Firebird+1 · Firebird+1
Published
2026-04-17
·
Updated
2026-05-15
·
CVE-2026-28224
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Firebird versions prior to 5.0.4
Firebird versions prior to 4.0.7
Firebird versions prior to 3.0.14
Description
An unauthenticated attacker can cause a server crash by sending an 'op crypt key callback' packet before authentication. This occurs because the
port server crypt callback() handler is not initialized, leading to a null pointer dereference, which is when a program attempts to read or write to a memory location using a pointer that is null.Recommendations
Update to version 5.0.4
Update to version 4.0.7
Update to version 3.0.14
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firebird
Red Os