ZDI-CAN-26486: ZDI-25-859: Firebird SQL Database Server XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Firebird SQL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-54989.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26486?
The severity of ZDI-CAN-26486 is rated at 7.5 on the CVSS scale, indicating a high risk.
How do I fix ZDI-CAN-26486?
To fix ZDI-CAN-26486, update your Firebird SQL Database Server to the latest version provided by the vendor.
Which software is affected by ZDI-CAN-26486?
ZDI-CAN-26486 affects the Firebird SQL Database Server without any specific version limitations.
Can ZDI-CAN-26486 be exploited remotely?
Yes, ZDI-CAN-26486 can be exploited remotely by attackers without the need for authentication.
What type of attack is associated with ZDI-CAN-26486?
ZDI-CAN-26486 is associated with a denial-of-service attack, which disrupts service availability.