Improper Check for Unusual or Exceptional Conditions in Firebird - CVE-2025-24975
Published: September 3, 2025
Vulnerability identifier: #VU114772
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24975
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper error handling when using ExtConnPool. A remote user can gain unauthorized access an encrypted database or crash the application.
Affected software
Firebird
Debian Linux
Fedora
firebird4.0 (Debian package)
firebird
Debian Linux
Fedora
firebird4.0 (Debian package)
firebird
How to mitigate CVE-2025-24975
Install updates from vendor's website.
firebird4.0 (Debian package) - update to 4.0.5.3140.ds6-17+deb13u1
firebird - addressed in versions 4.0.6.3221-1.fc41, 4.0.6.3221-1.fc42, 4.0.6.3221-1.fc43, 4.0.6.3221-1.1.el8, 4.0.6.3221-1.1.el9
firebird - addressed in versions 4.0.6.3221-1.fc41, 4.0.6.3221-1.fc42, 4.0.6.3221-1.fc43, 4.0.6.3221-1.1.el8, 4.0.6.3221-1.1.el9
External References
- https://github.com/FirebirdSQL/firebird/commit/658abd20449f72097fbbce57e8e6ae42ff837fb6
- https://github.com/FirebirdSQL/firebird/issues/8429
- https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-fx9r-rj68-7p69
- https://www.vicarius.io/vsociety/posts/cve-2025-24975-detect-vulnerable-firebird
- https://www.vicarius.io/vsociety/posts/cve-2025-24975-mitigate-firebird-vulnerability