Out-of-Bounds Affecting postgresql package, versions [7.2,8.0.1]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
57.06% (98th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-POSTGRESQL-2336082
  • published12 Jan 2022
  • disclosed2 May 2005
  • creditUnknown

Introduced: 2 May 2005

CVE-2005-0247  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

There is no fixed version for postgresql.

Overview

Affected versions of this package are vulnerable to Out-of-Bounds. Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.

CVSS Scores

version 3.1