NIXPKGS-2026-1188
GitHub issue
published on
Permalink
CVE-2025-65104
7.9 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): HIGH
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
ignored
3 packages
- firebird-emu
- firebird
- firebird_4
- @LeSuisse ignored reference https://g…
- @LeSuisse accepted
- @LeSuisse published on GitHub
Firebird: Information leak vulnerability in firebird3 client when used with newer server
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.
References
-
https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-mfpr-9886-xjhg x_refsource_CONFIRM
Ignored references (1)
-
https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.0 x_refsource_MISC
Affected products
firebird
- ==< 4.0.0
Matching in nixpkgs
Ignored packages (3)
pkgs.firebird
SQL relational database management system
pkgs.firebird_4
SQL relational database management system
Package maintainers
-
@bbenno Benno Bielmeier <nix@bbenno.com>
-
@MarcWeber Marc Weber <marco-oweber@gmx.de>