← Πίσω στην αναζήτηση CVE

CVE-2026-40342

Firebird

Περιγραφή

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library-s initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server-s OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS 9.9EPSS 0.692%Κίνδυνος 1.05
Προβολή πηγής
Δημοσίευση
2026-04-17 20:16:35
Επηρεαζόμενες εκδόσεις
<5.0.4,<4.0.7,<3.0.14
Τύπος
Package
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H