CVE-2002-1399 Affecting postgresql package, versions [,7.2.3)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
3.59% (92nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-POSTGRESQL-2336039
  • published12 Jan 2022
  • disclosed17 Jan 2003
  • creditUnknown

Introduced: 17 Jan 2003

CVE-2002-1399  (opens in a new tab)

How to fix?

Upgrade postgresql to version 7.2.3 or higher.

Overview

Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2).

CVSS Scores

version 3.1