5
CVSSv2

CVE-2012-1151

Published: 09/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module prior to 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

Vulnerable Product Search on Vulmon Subscribe to Product

perl perl 2.15.1

perl perl 2.15.0

perl perl 2.17.1

perl perl 2.17.0

perl perl 2.13.0

perl perl 2.12.0

perl perl 2.11.8

perl perl 2.11.1

perl perl 2.11.0

perl perl 2.10.1

perl perl 2.10.0

perl perl 2.8.5

perl perl 2.8.4

perl perl 2.8.3

perl perl 2.6.6

perl perl 2.6.5

perl perl 2.5.0

perl perl 2.4.0

perl perl 2.1.0

perl perl 2.0.0

perl perl 1.43

perl perl 1.42

perl perl 1.20

perl perl 1.01

perl perl 0.93

perl perl 0.92

perl perl 0.85

perl perl 0.84

perl perl 0.71

perl perl 0.70

perl perl 0.62

perl perl 0.61

perl perl

perl perl 2.11.5

perl perl 2.11.4

perl perl 2.10.5

perl perl 2.10.4

perl perl 2.9.0

perl perl 2.8.8

perl perl 2.8.0

perl perl 2.7.2

perl perl 2.6.2

perl perl 2.6.1

perl perl 2.2.1

perl perl 2.2.0

perl perl 1.47

perl perl 1.46

perl perl 1.32

perl perl 1.31

perl perl 0.98

perl perl 0.97

perl perl 0.96

perl perl 0.89

perl perl 0.88

perl perl 0.81

perl perl 0.80

perl perl 0.66

perl perl 0.65

perl perl 0.4

perl perl 0.3

perl perl 2.16.1

perl perl 2.16.0

perl perl 2.11.7

perl perl 2.11.6

perl perl 2.10.7

perl perl 2.10.6

perl perl 2.9.2

perl perl 2.9.1

perl perl 2.8.2

perl perl 2.8.1

perl perl 2.6.4

perl perl 2.6.3

perl perl 2.3.0

perl perl 2.2.2

perl perl 1.49

perl perl 1.48

perl perl 1.41

perl perl 1.40

perl perl 1.00

perl perl 0.99

perl perl 0.91

perl perl 0.90

perl perl 0.83

perl perl 0.82

perl perl 0.69

perl perl 0.68

perl perl 0.67

perl perl 0.52

perl perl 0.5

perl perl 2.18.0

perl perl 2.17.2

perl perl 2.14.1

perl perl 2.14.0

perl perl 2.11.3

perl perl 2.11.2

perl perl 2.10.3

perl perl 2.10.2

perl perl 2.8.7

perl perl 2.8.6

perl perl 2.7.1

perl perl 2.7.0

perl perl 2.6.0

perl perl 2.5.1

perl perl 2.1.3

perl perl 2.1.2

perl perl 2.1.1

perl perl 1.45

perl perl 1.44

perl perl 1.22

perl perl 1.21

perl perl 0.95

perl perl 0.94

perl perl 0.87

perl perl 0.86

perl perl 0.73

perl perl 0.72

perl perl 0.64

perl perl 0.63

perl perl 0.2

perl perl 0.1

Vendor Advisories

Synopsis Moderate: perl-DBD-Pg security update Type/Severity Security Advisory: Moderate Topic An updated perl-DBD-Pg package that fixes two security issues is nowavailable for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Comm ...
Debian Bug report logs - #661536 libdbd-pg-perl: CVE-2012-1151: Format string vulnerabilities in server error parsing Package: src:libdbd-pg-perl; Maintainer for src:libdbd-pg-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Reported by: Dominic Hargreaves <dom@earthli> Date: Mon, 27 Feb 2012 ...
Niko Tyni discovered two format string vulnerabilities in DBD::Pg, a Perl DBI driver for the PostgreSQL database server, which can be exploited by a rogue database server For the stable distribution (squeeze), this problem has been fixed in version 2171-2+squeeze1 For the unstable distribution (sid), this problem has been fixed in version 219 ...
Two format string flaws were found in perl-DBD-Pg A specially-crafted database warning or error message from a server could cause an application using perl-DBD-Pg to crash or, potentially, execute arbitrary code with the privileges of the user running the application (CVE-2012-1151) ...