Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4282-1 | firebird3.0 security update |
Debian DSA |
DSA-5992-1 | firebird4.0 security update |
EUVD |
EUVD-2025-25032 | Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 21 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* |
Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Firebirdsql
Firebirdsql firebird |
|
| Vendors & Products |
Firebirdsql
Firebirdsql firebird |
Fri, 15 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3. | |
| Title | Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T18:13:39.162Z
Reserved: 2025-08-04T17:34:24.419Z
Link: CVE-2025-54989
Updated: 2025-08-15T19:08:28.671Z
Status : Modified
Published: 2025-08-15T15:15:32.597
Modified: 2025-11-03T19:16:11.913
Link: CVE-2025-54989
No data.
OpenCVE Enrichment
Updated: 2025-08-16T21:40:47Z
Debian DLA
Debian DSA
EUVD