CVE-2023-41038 - CVE House
Back to Database
Status published High CVE-2023-41038

Server crash when using specific form of SET BIND statement

Vulnerability Description

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific form of SET BIND statement. Any non-privileged user with minimum access to a server may type a statement with a long `CHAR` length, which causes the server to crash due to stack corruption. Versions 4.0.4.2981 and 5.0.0.117 contain fixes for this issue. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-41038

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

FirebirdSQL

View all reports →

Affected Software

firebird
Vulnerable Versions:
>= 4.0.0, < 4.0.4.2981, >= 5.0 beta1, < 5.0.0.1176

Timeline

Official Publish: March 20th, 2024
Last Modified: August 13th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)