Debian LTS Advisory DLA-2824-1
Sylvain Beucler
November 20, 2021
Package        : firebird3.0
Version        :
CVE ID         : CVE-2017-11509

An authenticated remote attacker can execute arbitrary code in
Firebird, a relational database based on InterBase 6.0, by executing a
malformed SQL statement. The only known solution is to disable
external UDF libraries from being loaded. In order to achieve this,
the default configuration has changed to UdfAccess=None. This will
prevent the fbudf module from being loaded, but may also break other
functionality relying on modules.

For Debian 9 stretch, this problem has been fixed in version

We recommend that you upgrade your firebird3.0 packages.

