CVE-2009-2620

src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
firebirdsqlfirebird
𝑥
≤ 2.0.3
firebirdsqlfirebird
1.5
firebirdsqlfirebird
1.5.1
firebirdsqlfirebird
1.5.2
firebirdsqlfirebird
1.5.2.4731
firebirdsqlfirebird
1.5.3.4870
firebirdsqlfirebird
1.5.4.4910
firebirdsqlfirebird
1.5.5
firebirdsqlfirebird
2.0.0
firebirdsqlfirebird
2.0.0.12748
firebirdsqlfirebird
2.0.1
firebirdsqlfirebird
2.0.2
firebirdsqlfirebird
2.1
firebirdsqlfirebird
2.1.2
firebirdsqlfirebird
2.1.3:rc1
firebirdsqlfirebird
2.5
firebirdsqlfirebird
2.5:beta_2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firebird2.0
oneiric
dne
natty
dne
maverick
dne
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
dne
firebird2.1
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
dne
dapper
dne