CVE Vulnerabilities

CVE-2014-9323

NULL Pointer Dereference

Published: Dec 16, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FirebirdFirebirdsql*2.1.7 (excluding)
FirebirdFirebirdsql2.5 (including)2.5.3 (including)
Firebird2.0Ubuntulucid*
Firebird2.0Ubuntuupstream*
Firebird2.1Ubuntulucid*
Firebird2.1Ubuntuprecise*
Firebird2.1Ubuntuupstream*
Firebird2.5Ubuntuesm-infra-legacy/trusty*
Firebird2.5Ubuntuprecise*
Firebird2.5Ubuntutrusty*
Firebird2.5Ubuntutrusty/esm*
Firebird2.5Ubuntuupstream*
Firebird2.5Ubuntuutopic*

Potential Mitigations

References