Incorrect calculation in Firebird - CVE-2025-65104
Published: April 20, 2026
Firebird
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information and modify data.
The vulnerability exists due to improper data length handling in XSQLDA fields when processing responses from a Firebird 4 or higher server. A local user can use the firebird3 client with a newer server to disclose sensitive information and modify data.
The issue occurs when the firebird3 client is used with a Firebird 4 or higher server.