PT-2002-1017 · Postgresql · Ecpg+1

Publicado

2002-08-23

·

Atualizado

2016-10-18

·

CVE-2002-0972

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL version 7.2 ecpg (affected versions not specified)
Description The issue involves buffer overflows in PostgreSQL, potentially allowing attackers to cause a denial of service or execute arbitrary code by providing long arguments to functions such as lpad or rpad. Additionally, there are multiple vulnerabilities in the ecpg package that can lead to breaches of confidentiality, integrity, and availability of protected information, with the possibility of remote exploitation.
Recommendations For PostgreSQL version 7.2, consider restricting the use of the lpad and rpad functions until a patch is available. For ecpg, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03115
CVE-2002-0972
DSA-165

Produtos afetados

Postgresql
Ecpg