[Git][security-tracker-team/security-tracker][master] Add CVE-2025-24975/firebird4.0

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 15 21:52:45 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9a2e2367 by Salvatore Bonaccorso at 2025-08-15T22:52:36+02:00
Add CVE-2025-24975/firebird4.0

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -97,7 +97,12 @@ CVE-2025-36088 (IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00
 CVE-2025-26709 (There is an unauthorized access vulnerability in ZTE F50. Due to impro ...)
 	NOT-FOR-US: ZTE
 CVE-2025-24975 (Firebird is a relational database. Prior to snapshot versions 4.0.6.31 ...)
-	TODO: check
+	- firebird3.0 <undetermined>
+	- firebird4.0 <unfixed>
+	NOTE: https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-fx9r-rj68-7p69
+	NOTE: https://github.com/FirebirdSQL/firebird/issues/8429
+	NOTE: https://github.com/FirebirdSQL/firebird/commit/658abd20449f72097fbbce57e8e6ae42ff837fb6
+	TODO: check status for src:firebird3.0, upstream suggests 4.0.0 onwards
 CVE-2025-1929 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: Reel SEktor hazine ve Risk Yonetimi Yazilimi
 CVE-2024-12573



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a2e2367ccb1966449cd802ffa03921aaa94c149

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a2e2367ccb1966449cd802ffa03921aaa94c149
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250815/166ae7be/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list