CVE-2009-2943 Affecting postgresql-ocaml package, versions <1.12.1-1


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.62% (79th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-POSTGRESQLOCAML-263605
  • published22 Oct 2009
  • disclosed22 Oct 2009

Introduced: 22 Oct 2009

CVE-2009-2943  (opens in a new tab)

How to fix?

Upgrade Debian:10 postgresql-ocaml to version 1.12.1-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream postgresql-ocaml package and not the postgresql-ocaml package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS Scores

version 3.1