CVE-2009-2620

EUVD-2009-2615
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
firebirdsqlfirebird
1.5 ≤
𝑥
< 1.5.6
firebirdsqlfirebird
2.0.0 ≤
𝑥
< 2.0.6
firebirdsqlfirebird
2.1 ≤
𝑥
< 2.1.3
firebirdsqlfirebird
2.5.0
firebirdsqlfirebird
2.5.0:alpha1
firebirdsqlfirebird
2.5.0:beta1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firebird2.0
dapper
dne
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
not-affected
maverick
dne
natty
dne
oneiric
dne
firebird2.1
dapper
dne
hardy
dne
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected