CVE-2023-41038: Server crash when using specific form of SET BIND statement
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long CHAR length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41038?
CVE-2023-41038 is classified as a server crash vulnerability affecting Firebird Database versions 4.0.0 through 4.0.3 and version 5.0 beta1.
How do I fix CVE-2023-41038?
To mitigate CVE-2023-41038, upgrade to Firebird Database version 4.0.4 or later.
Who is affected by CVE-2023-41038?
Any non-privileged user with minimum access to the Firebird server can exploit CVE-2023-41038.
What can exploit CVE-2023-41038?
CVE-2023-41038 can be exploited through a specific form of SET BIND statement that includes an excessively long CHAR length.
When was CVE-2023-41038 disclosed?
CVE-2023-41038 was disclosed in 2023, affecting specific releases of the Firebird Database.