ZDI-25-859: Firebird SQL Database Server XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
Published Aug 21, 2025
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Firebird SQL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-54989.
Affected Software
1 affected component
Firebird Firebird SQL Database Server
Event History
Aug 21, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-859?
ZDI-25-859 has a CVSS rating of 7.5, indicating a high severity level.
2
What type of attack does ZDI-25-859 enable?
ZDI-25-859 allows remote attackers to create a denial-of-service condition.
3
Is authentication required to exploit ZDI-25-859?
No, authentication is not required to exploit ZDI-25-859.
4
What software is affected by ZDI-25-859?
ZDI-25-859 affects installations of Firebird SQL Database Server.
5
How can I mitigate the risk of ZDI-25-859?
To mitigate ZDI-25-859, ensure your Firebird SQL Database Server is updated to the latest version with security patches.