PT-2002-1017 · Postgresql · Ecpg+1

Published

2002-08-23

·

Updated

2016-10-18

·

CVE-2002-0972

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL version 7.2 ecpg (affected versions not specified)
Description The issue involves buffer overflows in PostgreSQL, potentially allowing attackers to cause a denial of service or execute arbitrary code by providing long arguments to functions such as lpad or rpad. Additionally, there are multiple vulnerabilities in the ecpg package that can lead to breaches of confidentiality, integrity, and availability of protected information, with the possibility of remote exploitation.
Recommendations For PostgreSQL version 7.2, consider restricting the use of the lpad and rpad functions until a patch is available. For ecpg, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03115
CVE-2002-0972
DSA-165

Affected Products

Postgresql
Ecpg