PT-2002-1019 · Postgresql+1 · Ecpg+2

Published

2002-09-24

·

Updated

2016-10-18

·

CVE-2002-1400

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 7.2.2 ecpg (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the ecpg package of Debian GNU/Linux and a heap-based buffer overflow in the repeat() function of PostgreSQL. This can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations For PostgreSQL versions prior to 7.2.2: update to version 7.2.2 or later to resolve the issue. For ecpg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03115
CVE-2002-1400
DSA-165

Affected Products

Debian
Postgresql
Ecpg