UBUNTU-CVE-2025-54989

Source
https://ubuntu.com/security/CVE-2025-54989
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54989.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-54989
Upstream
Published
2025-08-15T15:15:00Z
Modified
2025-08-27T18:40:25Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3.

References

Affected packages

Ubuntu:Pro:18.04:LTS / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/ubuntu/firebird3.0@3.0.2.32703.ds4-11ubuntu2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.2.32703.ds4-9
3.0.2.32703.ds4-11ubuntu1
3.0.2.32703.ds4-11ubuntu2

Ubuntu:Pro:20.04:LTS / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/ubuntu/firebird3.0@3.0.5.33220.ds4-1build2?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.5.33100.ds4-3
3.0.5.33189.ds4-1
3.0.5.33209.ds4-1
3.0.5.33220.ds4-1
3.0.5.33220.ds4-1build1
3.0.5.33220.ds4-1build2

Ubuntu:22.04:LTS / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/ubuntu/firebird3.0@3.0.8.33535.ds4-1ubuntu2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.7.33374.ds4-2
3.0.8.33535.ds4-1ubuntu1
3.0.8.33535.ds4-1ubuntu2

Ubuntu:24.04:LTS / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/ubuntu/firebird3.0@3.0.11.33703.ds4-2ubuntu2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.11.33637.ds4-2ubuntu1
3.0.11.33637.ds4-2ubuntu2
3.0.11.33703.ds4-2ubuntu1
3.0.11.33703.ds4-2ubuntu2

Ubuntu:25.04 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/ubuntu/firebird3.0@3.0.12.ds7-12?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.11.33703.ds4-2ubuntu2
3.0.12.ds7-5+exp1
3.0.12.ds7-7+exp1
3.0.12.ds7-8
3.0.12.ds7-9
3.0.12.ds7-10
3.0.12.ds7-11
3.0.12.ds7-12

Ubuntu:25.04 / firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/ubuntu/firebird4.0@4.0.5.3140.ds6-16?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.0.5.3140.ds6-9ubuntu1
4.0.5.3140.ds6-10
4.0.5.3140.ds6-11
4.0.5.3140.ds6-12
4.0.5.3140.ds6-13
4.0.5.3140.ds6-14
4.0.5.3140.ds6-15
4.0.5.3140.ds6-16