ZDI-CAN-26486: XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
Package
Any firebird version before the fix
Affected versions
Any firebird version before the fix
Patched versions
5.0.3 / 4.0.6 / 3.0.13
Impact
The specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS.
Patches
Currently one can use the following or later point releases: