The xdrstatusvector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
{
"binaries": [
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird-dev"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-classic"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-classic-common"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-common"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-examples"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-server-common"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-super"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "firebird2.5-superclassic"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "libfbclient2"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "libfbembed2.5"
},
{
"binary_version": "2.5.2.26540.ds4-9ubuntu1.1",
"binary_name": "libib-util"
}
],
"availability": "No subscription required"
}