Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2009-1067.html | vendor advisory |
http://www.securityfocus.com/bid/34757 | vdb entry |
http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz | |
https://launchpad.net/bugs/cve/2009-1341 | |
http://secunia.com/advisories/34909 | third party advisory vendor advisory |
http://www.redhat.com/support/errata/RHSA-2009-0479.html | vendor advisory |
http://secunia.com/advisories/35685 | third party advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9680 | vdb entry signature |
http://cpansearch.perl.org/src/TURNSTEP/DBD-Pg-2.13.1/Changes | |
http://www.debian.org/security/2009/dsa-1780 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html | vendor advisory |
http://secunia.com/advisories/35058 | third party advisory vendor advisory |
http://rt.cpan.org/Public/Bug/Display.html?id=21392 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50387 | vdb entry |