CVE-2021-21704: Multiple vulnerabilities in Firebird client extension
Fixed bug (Crash while parsing blob data in firebirdfetchblob). (CVE-2021-21704)
Other sources
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.
— MITRE
Multiple vulnerabilities in Firebird client extension
— Microsoft
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21704?
The severity of CVE-2021-21704 is medium with a CVSS score of 5.9.
What is the affected software for CVE-2021-21704?
The affected software for CVE-2021-21704 is PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21, and 8.0.x below 8.0.8, as well as NetApp Clustered Data ONTAP.
How can a malicious database server exploit CVE-2021-21704?
A malicious database server can exploit CVE-2021-21704 by returning invalid response data that can cause crashes in various database functions.
Are there any known fixes for CVE-2021-21704?
Yes, the fix for CVE-2021-21704 is available in PHP version 8.0.8.
Where can I find more information about CVE-2021-21704?
You can find more information about CVE-2021-21704 on the PHP website and the bug report links provided.