PT-2026-33480 · Firebird+1 · Firebird+1

Published

2026-04-17

·

Updated

2026-05-15

·

CVE-2026-28224

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Firebird versions prior to 5.0.4 Firebird versions prior to 4.0.7 Firebird versions prior to 3.0.14
Description An unauthenticated attacker can cause a server crash by sending an 'op crypt key callback' packet before authentication. This occurs because the port server crypt callback() handler is not initialized, leading to a null pointer dereference, which is when a program attempts to read or write to a memory location using a pointer that is null.
Recommendations Update to version 5.0.4 Update to version 4.0.7 Update to version 3.0.14

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-05711
CVE-2026-28224
OESA-2026-2013
OESA-2026-2014
OESA-2026-2015
OESA-2026-2016
OESA-2026-2017

Affected Products

Firebird
Red Os