CVE-2025-65104

7.9

FirebirdSQL · Firebird

A flaw in the Firebird client library causes incorrect data length values in XSQLDA fields during server communication, leading to sensitive information exposure.

Executive summary

An information disclosure vulnerability in the Firebird client library allows local authenticated attackers to access sensitive data, necessitating an immediate upgrade to version 4.0.0 or higher.

Vulnerability

This vulnerability involves the improper handling of data length values in XSQLDA fields when a client library communicates with a version 4.0.0 or higher server. The flaw permits an authenticated local attacker to trigger an information leak.

Business impact

The vulnerability carries a CVSS score of 7.9, indicating a high level of severity due to its potential impact on data confidentiality. Successful exploitation could lead to the unauthorized exposure of sensitive information processed within the database communication layer, potentially compromising proprietary data and weakening overall system security posture.

Remediation

Immediate Action: Upgrade the Firebird client library to version 4.0.0 or higher to ensure correct data length handling during server communication.

Proactive Monitoring: Review database access logs for unusual patterns or errors associated with client library communication sessions that may indicate unauthorized data access attempts.

Compensating Controls: Ensure that access to the database server is restricted to authorized users and processes, and implement strict local system controls to limit the privileges of potential attackers on the host.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity and the nature of the information disclosure, organizations should prioritize the update of the Firebird client library. Organizations running older versions of the client against upgraded Firebird 4.0.0 or higher servers are at the highest risk and should schedule maintenance to apply the fix as soon as possible.

Sources