PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://trac.osgeo.org/postgis/changeset/15444 | third party advisory patch |
https://trac.osgeo.org/postgis/changeset/15445 | third party advisory patch |
https://lists.debian.org/debian-lts-announce/2019/01/msg00030.html | third party advisory mailing list |
https://trac.osgeo.org/postgis/ticket/3704 | third party advisory exploit |
https://lists.debian.org/debian-lts-announce/2021/12/msg00020.html | third party advisory mailing list |