CVE-2025-24975
Last modified
CVE-2025-24975 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connections stored in ExtConnPool are not verified for presence and suitability of the CryptCallback interface is used when created versus what is available could result in a segfault in the server process. Encrypted databases, accessed by execute statement on external, may be accessed later by an attachment missing a key to that database. In a case when execute statement are chained, segfault may happen. Additionally, the segfault may affect unencrypted databases. This issue has been patched in snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609 and point releases 4.0.6 and 5.0.2. A workaround for this issue involves setting ExtConnPoolSize equal to 0 in firebird.conf.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Firebirdsql | Firebird | >= 4.0.0, < 4.0.6 |
| Firebirdsql | Firebird | >= 5.0.0, < 5.0.2 |
References
- https://github.com/FirebirdSQL/firebird/issues/8429Issue Tracking
- https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-fx9r-rj68-7p69Mitigation, Vendor Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-24975-detect-vulnerable-firebirdExploit, Third Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-24975-mitigate-firebird-vulnerabilityExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-24975?
How severe is CVE-2025-24975?
How do I fix CVE-2025-24975?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-2497A maliciously crafted DWG file, when parsed through Autodesk…7.8
- CVE-2025-24970Netty, an asynchronous, event-driven network application fra…7.5
- CVE-2025-24971DumpDrop is a stupid simple file upload application that pro…9.5
- CVE-2025-24972Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2025-24973Concorde, formerly know as Nexkey, is a fork of the federate…9.3
- CVE-2025-24974DataEase is an open source business intelligence and data vi…6.5
- CVE-2025-24976Distribution is a toolkit to pack, ship, store, and deliver …6.6
- CVE-2025-24977OpenCTI is an open cyber threat intelligence (CTI) platform.…9.1
- CVE-2025-2498An improper access control in Gitlab EE affecting all versio…4.3
- CVE-2025-24980pimcore/admin-ui-classic-bundle provides a Backend UI for Pi…5.3
- CVE-2025-24981MDC is a tool to take regular Markdown and write documents i…9.3
- CVE-2025-24982Cross-site request forgery vulnerability exists in Activity …4.3
Are you affected by CVE-2025-24975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
