6.5
CVSSv2

CVE-2005-0247

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and previous versions may allow malicious users to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 7.2.6

postgresql postgresql 7.2.7

postgresql postgresql 7.3.7

postgresql postgresql 7.3.8

postgresql postgresql 7.4.5

postgresql postgresql 7.4.6

postgresql postgresql 7.2.4

postgresql postgresql 7.2.5

postgresql postgresql 7.3.4

postgresql postgresql 7.3.5

postgresql postgresql 7.2

postgresql postgresql 7.2.1

postgresql postgresql 7.3

postgresql postgresql 7.3.1

postgresql postgresql 7.3.9

postgresql postgresql 7.4

postgresql postgresql 7.4.7

postgresql postgresql 8.0.0

postgresql postgresql 7.2.2

postgresql postgresql 7.2.3

postgresql postgresql 7.3.2

postgresql postgresql 7.3.3

postgresql postgresql 7.4.1

postgresql postgresql 7.4.2

postgresql postgresql 8.0.1

postgresql postgresql 7.3.6

postgresql postgresql 7.4.3

postgresql postgresql 7.4.4

Vendor Advisories

The execution of custom PostgreSQL functions can be restricted with the EXECUTE privilege However, previous versions did not check this privilege when executing a function which was part of an aggregate As a result, any database user could circumvent the EXECUTE restriction of functions with a particular (but very common) parameter structure by c ...
Synopsis postgresql security update Type/Severity Security Advisory: Important Topic Updated PostgreSQL packages to fix various security flaws are now availablefor Red Hat Enterprise Linux 21ASThis update has been rated as having important security impact by the RedHat Security Response Team Des ...
Synopsis rh-postgresql security update Type/Severity Security Advisory: Important Topic Updated PostgreSQL packages to fix various security flaws are now availablefor Red Hat Enterprise Linux 3 Description PostgreSQL is an advanced Object-Relational database management system(DBMS)A flaw ...
Synopsis postgresql security update Type/Severity Security Advisory: Important Topic Updated postresql packages that correct various security issues are nowavailable for Red Hat Enterprise Linux 4This update has been rated as having important security impact by the RedHat Security Response Team D ...
Several buffer overflows have been discovered in PL/PgSQL as part of the PostgreSQL engine which could lead to the execution of arbitrary code For the stable distribution (woody) these problems have been fixed in version 721-2woody8 For the unstable distribution (sid) these problems have been fixed in version 747-2 We recommend that you upgr ...