6.5
CVSSv2

CVE-2002-1401

Published: 17/01/2003 Updated: 10/09/2008
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and previous versions allow malicious users to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 7.2.3

postgresql postgresql 7.1.3

postgresql postgresql 7.2.1

postgresql postgresql 6.5.3

postgresql postgresql 7.0.3

postgresql postgresql 7.1

postgresql postgresql 7.1.1

postgresql postgresql 7.1.2

postgresql postgresql 6.3.2

postgresql postgresql 7.2

postgresql postgresql 7.2.2

Vendor Advisories

Mordred Labs and others found several vulnerabilities in PostgreSQL, an object-relational SQL database They are inherited from several buffer overflows and integer overflows Specially crafted long date and time input, currency, repeat data and long timezone names could cause the PostgreSQL server to crash as well as specially crafted input data f ...