7.5
CVSSv2

CVE-2005-1409

Published: 03/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PostgreSQL 7.3.x up to and including 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 7.2.1

postgresql postgresql 7.2.2

postgresql postgresql 7.3.1

postgresql postgresql 7.3.2

postgresql postgresql 7.3.9

postgresql postgresql 7.4

postgresql postgresql 8.0

postgresql postgresql 8.0.1

postgresql postgresql 7.2.3

postgresql postgresql 7.2.4

postgresql postgresql 7.3.3

postgresql postgresql 7.3.4

postgresql postgresql 7.4.1

postgresql postgresql 7.4.2

postgresql postgresql 8.0.2

postgresql postgresql 7.2.7

postgresql postgresql 7.3

postgresql postgresql 7.3.7

postgresql postgresql 7.3.8

postgresql postgresql 7.4.6

postgresql postgresql 7.4.7

postgresql postgresql 7.2.5

postgresql postgresql 7.2.6

postgresql postgresql 7.3.5

postgresql postgresql 7.3.6

postgresql postgresql 7.4.3

postgresql postgresql 7.4.4

postgresql postgresql 7.4.5

Vendor Advisories

Synopsis postgresql security update Type/Severity Security Advisory: Moderate Topic Updated postgresql packages that fix several security vulnerabilities andrisks of data loss are now availableThis update has been rated as having moderate security impact by the RedHat Security Response Team Descr ...
It was discovered that unprivileged users were allowed to call internal character conversion functions However, since these functions were not designed to be safe against malicious choices of argument values, this could potentially be exploited to execute arbitrary code with the privileges of the PostgreSQL server (user “postgres”) (CAN-2005- ...