CVE Vulnerabilities

CVE-2009-2943

Published: Oct 22, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

Affected Software

NameVendorStart VersionEnd Version
Postgresql-ocamlOcaml1.5.4 (including)1.5.4 (including)
Postgresql-ocamlOcaml1.7.0 (including)1.7.0 (including)
Postgresql-ocamlOcaml1.12.1 (including)1.12.1 (including)
Postgresql-ocamlUbuntudapper*
Postgresql-ocamlUbuntuhardy*
Postgresql-ocamlUbuntuintrepid*
Postgresql-ocamlUbuntujaunty*
Postgresql-ocamlUbuntukarmic*
Postgresql-ocamlUbuntuupstream*

References