← Späť na vyhľadávanie CVE

CVE-2026-27890

Firebird

Popis

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class-s grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server-s IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS 8.2EPSS 0.46499999999999997%Riziko 0.85
Zobraziť zdroj
Zverejnené
2026-04-17 19:16:34
Dotknuté verzie
<5.0.4,<4.0.7,<3.0.14
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H