Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45573 | Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 03 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* cpe:2.3:a:firebirdsql:firebird:5.0:beta1:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-13T16:44:27.739Z
Reserved: 2023-08-22T16:57:23.932Z
Link: CVE-2023-41038
Updated: 2024-08-02T18:46:11.557Z
Status : Analyzed
Published: 2024-03-20T15:15:07.290
Modified: 2025-12-03T20:03:05.223
Link: CVE-2023-41038
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:25Z
Weaknesses
EUVD