Impact
The vulnerability occurs when the Firebird server processes an op_slice network packet. The server passes an unprepared structure containing a null pointer to the SDL_info() function, which triggers a dereference and causes the server to crash. An attacker does not need authentication; by sending a crafted packet to the server port, the process terminates. The effect is a denial‑of‑service condition; there is no direct compromise of data confidentiality or integrity.
Affected Systems
FirebirdSQL’s Firebird relational database server is impacted. Versions earlier than 6.0.0, 5.0.4, 4.0.7, and 3.0.14 contain the flaw. All releases 6.0.0 and later are considered fixed and not vulnerable.
Risk and Exploitability
A CVSS score of 7.5 classifies this as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no documented exploitation to date. The attack vector is a remote, unauthenticated network attacker who can initiate the crash by sending a malformed op_slice packet to the Firebird port without any additional privileges.
OpenCVE Enrichment