DEBIAN-CVE-2025-54989

Source
https://security-tracker.debian.org/tracker/CVE-2025-54989
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-54989
Upstream
Published
2025-08-15T15:15:32.597Z
Modified
2025-11-20T10:18:25.076853Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3.

References

Affected packages

Debian:11

firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.7.33374.ds4-2+deb11u1

Affected versions

3.*

3.0.7.33374.ds4-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json"

Debian:12

firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.11.33637.ds4-2+deb12u1

Affected versions

3.*

3.0.11.33637.ds4-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json"

Debian:13

firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.12.ds7-13+deb13u1

Affected versions

3.*

3.0.12.ds7-13

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json"

firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/debian/firebird4.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.5.3140.ds6-17+deb13u1

Affected versions

4.*

4.0.5.3140.ds6-17

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json"

Debian:14

firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.13.ds7-1

Affected versions

3.*

3.0.12.ds7-13
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json"

firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/debian/firebird4.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.6.3221.ds6-1

Affected versions

4.*

4.0.5.3140.ds6-17
4.0.5.3140.ds6-17+m68k

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54989.json"