본문 바로가기

취약점 정보1

PostgreSQL class C vulnerability in core server, ECPG: CVE-2014-0063

728x90

PostgreSQL class C vulnerability in core server, ECPG: CVE-2014-0063

SeverityCVSSPublishedAddedModified
7(AV:N/AC:L/Au:S/C:P/I:P/A:P)March 31, 2014April 01, 2014April 01, 2014

Description

Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065.

References

Solution

Related Vulnerabilities


728x90