PT-2015-3420 · Postgresql Global Development Group+4 · Postgresql+4

Publicado

2015-01-26

·

Atualizado

2024-06-15

·

CVE-2015-1352

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions through 5.6.7
Description The issue is related to the build tablename function in pgsql.c in the PostgreSQL extension in PHP, which does not validate token extraction for table names. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted name.
Recommendations For PHP versions through 5.6.7, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02523
CVE-2015-1352
DSA-3195-1
HPSBUX03337
MGASA-2015-0090
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
RHSA-2015:1053
SUSE-SU-2016:1638-1
USN-2501-1

Produtos afetados

Hp-Ux
Php
Postgresql
Suse
Ubuntu