PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A676 | signature vdb entry |
http://www.redhat.com/support/errata/RHSA-2005-433.html | vendor advisory |
http://www.securityfocus.com/archive/1/426302/30/6680/threaded | vendor advisory |
http://www.vupen.com/english/advisories/2005/0453 | vdb entry |
http://www.securityfocus.com/bid/13476 | vdb entry |
http://archives.postgresql.org/pgsql-announce/2005-05/msg00001.php | patch mailing list |
http://www.postgresql.org/about/news.315 | patch |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10050 | signature vdb entry |
http://www.novell.com/linux/security/advisories/2005_36_sudo.html | vendor advisory |