CVE-2025-54989

Source
https://cve.org/CVERecord?id=CVE-2025-54989
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54989.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54989
Aliases
  • GHSA-7qp6-hqxj-pjjp
Downstream
Related
Published
2025-08-15T15:04:19.097Z
Modified
2026-02-05T04:33:12.148590Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
Details

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54989.json"
}
References

Affected packages

Git / github.com/firebirdsql/firebird

Affected ranges

Type
GIT
Repo
https://github.com/firebirdsql/firebird
Events

Affected versions

v5.*
v5.0.0
v5.0.1
v5.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54989.json"