PT-2002-1019 · Postgresql+1 · Ecpg+2

Publicado

2002-09-24

·

Atualizado

2016-10-18

·

CVE-2002-1400

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 7.2.2 ecpg (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the ecpg package of Debian GNU/Linux and a heap-based buffer overflow in the repeat() function of PostgreSQL. This can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations For PostgreSQL versions prior to 7.2.2: update to version 7.2.2 or later to resolve the issue. For ecpg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03115
CVE-2002-1400
DSA-165

Produtos afetados

Debian
Postgresql
Ecpg