Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.
References
| Link | Resource |
|---|---|
| https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.0 | Product Release Notes |
| https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-mfpr-9886-xjhg | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-17 18:16
Updated : 2026-06-17 09:55
NVD link : CVE-2025-65104
Mitre link : CVE-2025-65104
CVE.ORG link : CVE-2025-65104
JSON object : View
Products Affected
firebirdsql
- firebird
CWE
