Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor is later used to calculate the number of slice items, causing a division by zero. An unauthenticated attacker can exploit this by sending a crafted slice packet to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Firebirdsql
Firebirdsql firebird |
|
| Vendors & Products |
Firebirdsql
Firebirdsql firebird |
Fri, 17 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor is later used to calculate the number of slice items, causing a division by zero. An unauthenticated attacker can exploit this by sending a crafted slice packet to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14. | |
| Title | Firebird: DoS via malicious slice descriptor in slice packet | |
| Weaknesses | CWE-369 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-17T18:59:23.663Z
Reserved: 2026-04-01T18:48:58.937Z
Link: CVE-2026-35215
No data.
Status : Received
Published: 2026-04-17T20:16:35.240
Modified: 2026-04-17T20:16:35.240
Link: CVE-2026-35215
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:30:15Z