CVE Vulnerabilities

CVE-2005-1410

Published: May 03, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as internal even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 7.4 (including) 7.4 (including)
Postgresql Postgresql 7.4.3 (including) 7.4.3 (including)
Postgresql Postgresql 7.4.5 (including) 7.4.5 (including)
Postgresql Postgresql 7.4.6 (including) 7.4.6 (including)
Postgresql Postgresql 7.4.7 (including) 7.4.7 (including)
Postgresql Postgresql 8.0 (including) 8.0 (including)
Postgresql Postgresql 8.0.1 (including) 8.0.1 (including)
Postgresql Postgresql 8.0.2 (including) 8.0.2 (including)
Red Hat Enterprise Linux 3 RedHat rh-postgresql-0:7.3.10-1 *
Red Hat Enterprise Linux 4 RedHat postgresql-0:7.4.8-1.RHEL4.1 *
Postgresql-7.4 Ubuntu dapper *
Postgresql-7.4 Ubuntu edgy *
Postgresql-8.0 Ubuntu dapper *
Postgresql-8.1 Ubuntu dapper *
Postgresql-8.1 Ubuntu devel *
Postgresql-8.1 Ubuntu edgy *
Postgresql-8.1 Ubuntu feisty *
Postgresql-8.2 Ubuntu devel *
Postgresql-8.2 Ubuntu feisty *

References