CVE-2023-41038
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2024
Last modified:
03/12/2025
Description
Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.3 (including) |
| cpe:2.3:a:firebirdsql:firebird:5.0:beta1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



