PT-2002-1019 · Postgresql+1 · Ecpg+2
Publicado
2002-09-24
·
Atualizado
2016-10-18
·
CVE-2002-1400
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions prior to 7.2.2
ecpg (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the ecpg package of Debian GNU/Linux and a heap-based buffer overflow in the repeat() function of PostgreSQL. This can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations
For PostgreSQL versions prior to 7.2.2: update to version 7.2.2 or later to resolve the issue.
For ecpg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Postgresql
Ecpg