Debian Security Advisory

DLA-1374-1 firebird2.5 -- LTS security update

Date Reported:
11 May 2018
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2017-11509.
More information:

An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement. The only known solution is to disable external UDF libraries from being loaded. In order to achieve this, the default configuration has changed to UdfAccess=None. This will prevent the fbudf module from being loaded, but may also break other functionality relying on modules.

For Debian 7 Wheezy, these problems have been fixed in version

We recommend that you upgrade your firebird2.5 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: