PT-2002-1021 · Postgresql+1 · Ecpg+2

Published

2002-09-24

·

Updated

2016-10-18

·

CVE-2002-1402

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 7.2.1 and earlier ecpg (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the ecpg package of Debian GNU/Linux and buffer overflows in PostgreSQL. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, buffer overflows in the TZ and SET TIME ZONE environment variables can cause a denial of service and possibly allow the execution of arbitrary code.
Recommendations For PostgreSQL versions 7.2.1 and earlier: update to a version later than 7.2.1 to resolve the buffer overflow issues in the TZ and SET TIME ZONE environment variables. For ecpg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03115
CVE-2002-1402
DSA-165

Affected Products

Debian
Postgresql
Ecpg