PT-2002-1019 · Postgresql+1 · Ecpg+2
Published
2002-09-24
·
Updated
2016-10-18
·
CVE-2002-1400
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions prior to 7.2.2
ecpg (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the ecpg package of Debian GNU/Linux and a heap-based buffer overflow in the repeat() function of PostgreSQL. This can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely.
Recommendations
For PostgreSQL versions prior to 7.2.2: update to version 7.2.2 or later to resolve the issue.
For ecpg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Postgresql
Ecpg