Denial of Service Vulnerability in Firebird SQL by Firebird
CVE-2009-2620

Currently unrated

Key Information:

Status
Vendor
CVE Published:
29 July 2009

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 10%

What is CVE-2009-2620?

A vulnerability exists in Firebird SQL due to improper handling of op_connect_request messages, which can be exploited by remote attackers to create a denial of service condition. When malformed requests are processed, they can result in an infinite loop or a NULL pointer dereference, leading to a crash of the Firebird SQL daemon. This makes the affected versions more susceptible to potential disruptions initiated by attackers. Users are advised to upgrade to the latest version to mitigate the risk.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.