Multiple vulnerabilities in Firebird client extension
Vulnerability Description
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-21704
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- reported by trichimtrich at gmail dot com
References
More from PHP Group
View All →Affected Vendor
PHP Group
View all reports →