CVE-2009-2940 Affecting pygresql package, versions <1:4.0-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.12% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN8-PYGRESQL-282837
  • published22 Oct 2009
  • disclosed22 Oct 2009

Introduced: 22 Oct 2009

CVE-2009-2940  (opens in a new tab)

How to fix?

Upgrade Debian:8 pygresql to version 1:4.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pygresql package and not the pygresql package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS Scores

version 3.1