CVE-2025-65104

NameCVE-2025-65104
DescriptionFirebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1134333

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firebird3.0 (PTS)bullseye3.0.7.33374.ds4-2vulnerable
bullseye (security)3.0.7.33374.ds4-2+deb11u1vulnerable
bookworm3.0.11.33637.ds4-2+deb12u1vulnerable
trixie3.0.12.ds7-13+deb13u1vulnerable
forky, sid3.0.14.ds7-1fixed
firebird4.0 (PTS)trixie (security), trixie4.0.5.3140.ds6-17+deb13u1fixed
forky, sid4.0.7.3271.ds6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firebird3.0source(unstable)3.0.14.ds7-11134333
firebird4.0source(unstable)(not affected)

Notes

- firebird4.0 <not-affected> (Vulnerable code not present)
https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-mfpr-9886-xjhg

Search for package or bug name: Reporting problems