PT-2002-1017 · Postgresql · Ecpg+1
Published
2002-08-23
·
Updated
2016-10-18
·
CVE-2002-0972
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PostgreSQL version 7.2
ecpg (affected versions not specified)
Description
The issue involves buffer overflows in PostgreSQL, potentially allowing attackers to cause a denial of service or execute arbitrary code by providing long arguments to functions such as
lpad or rpad. Additionally, there are multiple vulnerabilities in the ecpg package that can lead to breaches of confidentiality, integrity, and availability of protected information, with the possibility of remote exploitation.Recommendations
For PostgreSQL version 7.2, consider restricting the use of the
lpad and rpad functions until a patch is available.
For ecpg, at the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Postgresql
Ecpg