PT-2015-3420 · Postgresql Global Development Group+4 · Postgresql+4
Publicado
2015-01-26
·
Atualizado
2024-06-15
·
CVE-2015-1352
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions through 5.6.7
Description
The issue is related to the
build tablename function in pgsql.c in the PostgreSQL extension in PHP, which does not validate token extraction for table names. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted name.Recommendations
For PHP versions through 5.6.7, update to a version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hp-Ux
Php
Postgresql
Suse
Ubuntu