CVE Vulnerabilities

CVE-2005-1410

Published: May 03, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as internal even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.4 (including)7.4 (including)
PostgresqlPostgresql7.4.3 (including)7.4.3 (including)
PostgresqlPostgresql7.4.5 (including)7.4.5 (including)
PostgresqlPostgresql7.4.6 (including)7.4.6 (including)
PostgresqlPostgresql7.4.7 (including)7.4.7 (including)
PostgresqlPostgresql8.0 (including)8.0 (including)
PostgresqlPostgresql8.0.1 (including)8.0.1 (including)
PostgresqlPostgresql8.0.2 (including)8.0.2 (including)
Red Hat Enterprise Linux 3RedHatrh-postgresql-0:7.3.10-1*
Red Hat Enterprise Linux 4RedHatpostgresql-0:7.4.8-1.RHEL4.1*
Postgresql-7.4Ubuntudapper*
Postgresql-7.4Ubuntuedgy*
Postgresql-8.0Ubuntudapper*
Postgresql-8.1Ubuntudapper*
Postgresql-8.1Ubuntudevel*
Postgresql-8.1Ubuntuedgy*
Postgresql-8.1Ubuntufeisty*
Postgresql-8.2Ubuntudevel*
Postgresql-8.2Ubuntufeisty*

References