PT-2015-3420 · Postgresql Global Development Group+4 · Postgresql+4
Published
2015-01-26
·
Updated
2024-06-15
·
CVE-2015-1352
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions through 5.6.7
Description
The issue is related to the
build tablename function in pgsql.c in the PostgreSQL extension in PHP, which does not validate token extraction for table names. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted name.Recommendations
For PHP versions through 5.6.7, update to a version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux
Php
Postgresql
Suse
Ubuntu