DEBIAN-CVE-2026-33337

Source
https://security-tracker.debian.org/tracker/CVE-2026-33337
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33337.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-33337
Upstream
Published
2026-04-17T19:16:36Z
Modified
2026-09-14T17:03:28Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bounds, allowing a cstring longer than the allocated buffer to overflow it. An unauthenticated attacker can exploit this by sending a crafted packet to the server, potentially causing a crash or other security impact. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

References

Affected packages

Debian:12 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.11.33637.ds4-2
3.0.11.33637.ds4-2+deb12u1
3.0.11.33637.ds4-2+m68k
3.0.11.33637.ds4-2+m68k.1
3.0.11.33703.ds4-1
3.0.11.33703.ds4-2
3.0.11.33703.ds4-3
3.0.11.33703.ds4-3+exp.0
3.0.11.33703.ds4-3+exp.1
3.0.11.33703.ds4-3+m68k
3.0.11.33703.ds4-4
3.0.11.33703.ds4-4+exp.0
3.0.11.33703.ds4-4+m68k
3.0.12.ds5-1
3.0.12.ds5-2
3.0.12.ds7-1
3.0.12.ds7-2
3.0.12.ds7-3
3.0.12.ds7-3+exp.0
3.0.12.ds7-5
3.0.12.ds7-5+exp1
3.0.12.ds7-6
3.0.12.ds7-7
3.0.12.ds7-7+exp1
3.0.12.ds7-8
3.0.12.ds7-9
3.0.12.ds7-10
3.0.12.ds7-11
3.0.12.ds7-12
3.0.12.ds7-13
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1
3.0.13.ds7-1
3.0.13.ds7-2
3.0.14.ds7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33337.json"

Debian:13 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.12.ds7-13
3.0.12.ds7-13+deb13u1
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1
3.0.13.ds7-1
3.0.13.ds7-2
3.0.14.ds7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33337.json"

Debian:14 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.14.ds7-1

Affected versions

3.*
3.0.12.ds7-13
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1
3.0.13.ds7-1
3.0.13.ds7-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33337.json"

Debian:13 / firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/debian/firebird4.0?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.0.5.3140.ds6-17
4.0.5.3140.ds6-17+deb13u1
4.0.5.3140.ds6-17+m68k
4.0.6.3221.ds6-1
4.0.6.3221.ds6-2
4.0.7.3271.ds6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33337.json"

Debian:14 / firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/debian/firebird4.0?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.0.7.3271.ds6-1

Affected versions

4.*
4.0.5.3140.ds6-17
4.0.5.3140.ds6-17+m68k
4.0.6.3221.ds6-1
4.0.6.3221.ds6-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-33337.json"