CVE-2014-9323

Severity

50%

Complexity

99%

Confidentiality

48%

CWE-476: NULL Pointer Dereference

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.

CWE-476: NULL Pointer Dereference

CVSS 2.0 Base Score 5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).

Overview

First reported 10 years ago

2014-12-16 18:59:00

Last updated 5 years ago

2019-04-02 17:29:00

Affected Software

Firebird 2.5

2.5

Firebird 2.5.1

2.5.1

Firebird 2.5.2

2.5.2

Firebird 2.5.3

2.5.3

openSUSE Evergreen 11.4

11.4

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.