2.1
CVSSv2

CVE-2005-1410

Published: 03/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The tsearch2 module in PostgreSQL 7.4 up to and including 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows malicious users to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 8.0.1

postgresql postgresql 8.0.2

postgresql postgresql 7.4.5

postgresql postgresql 7.4.6

postgresql postgresql 7.4.7

postgresql postgresql 8.0

postgresql postgresql 7.4

postgresql postgresql 7.4.3

trustix secure linux 2.0

Vendor Advisories

Synopsis postgresql security update Type/Severity Security Advisory: Moderate Topic Updated postgresql packages that fix several security vulnerabilities andrisks of data loss are now availableThis update has been rated as having moderate security impact by the RedHat Security Response Team Descr ...
It was discovered that unprivileged users were allowed to call internal character conversion functions However, since these functions were not designed to be safe against malicious choices of argument values, this could potentially be exploited to execute arbitrary code with the privileges of the PostgreSQL server (user “postgres”) (CAN-2005- ...