PT-2015-3420 · Postgresql Global Development Group+4 · Postgresql+4

Published

2015-01-26

·

Updated

2024-06-15

·

CVE-2015-1352

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions through 5.6.7
Description The issue is related to the build tablename function in pgsql.c in the PostgreSQL extension in PHP, which does not validate token extraction for table names. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted name.
Recommendations For PHP versions through 5.6.7, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02523
CVE-2015-1352
DSA-3195-1
HPSBUX03337
MGASA-2015-0090
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
RHSA-2015:1053
SUSE-SU-2016:1638-1
USN-2501-1

Affected Products

Hp-Ux
Php
Postgresql
Suse
Ubuntu