CVE-2021-21704

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-21704

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-21704.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202107-15

OS impact

OSVersionStatusFixed in
arch archfixed8.0.8-1
suse slesaffected
debian debianbullseyefixed7.4.21-1+deb11u1

References

Verify integrity in audit chain (admin only). AS-IS.