|
|
| |
|
| |
postgresql: information disclosure/denial of service
| Package(s): | postgresql |
CVE #(s): | CVE-2013-0255
|
| Created: | February 11, 2013 |
Updated: | February 21, 2013 |
| Description: |
From the Red Hat bugzilla:
An array index error, leading to out of heap-based buffer bounds read flaw was found in the way PostgreSQL, an advanced Object-Relational database management system (DBMS), performed retrieval of textual form of error message representation when processing certain enumeration types. An unprivileged database user could issue a specially-crafted SQL query that, when processed by the server component of the PostgreSQL service, would lead to denial of service (daemon crash) or disclosure (of certain portions of) server memory. |
| Alerts: |
|
( Log in to post comments)
|
|
|