The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firebird | Firebirdsql | * | 2.1.7 (excluding) |
Firebird | Firebirdsql | 2.5 (including) | 2.5.3 (including) |
Firebird2.0 | Ubuntu | lucid | * |
Firebird2.0 | Ubuntu | upstream | * |
Firebird2.1 | Ubuntu | lucid | * |
Firebird2.1 | Ubuntu | precise | * |
Firebird2.1 | Ubuntu | upstream | * |
Firebird2.5 | Ubuntu | precise | * |
Firebird2.5 | Ubuntu | trusty | * |
Firebird2.5 | Ubuntu | upstream | * |
Firebird2.5 | Ubuntu | utopic | * |