PT-2026-33483 · Firebirdsql · Firebird
Published
2026-04-17
·
Updated
2026-04-17
·
CVE-2026-34232
CVSS v3.1
7.5
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr status vector() function does not handle the isc arg cstring type when decoding an op response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firebird