CVE Database
/

CVE-2006-2314

Back to search

CVE-2006-2314

Published: May 24, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-200607-04
vendor-advisory
x_refsource_GENTOO
20435
third-party-advisory
x_refsource_SECUNIA
18092
vdb-entry
x_refsource_BID
20503
third-party-advisory
x_refsource_SECUNIA
20451
third-party-advisory
x_refsource_SECUNIA
21001
third-party-advisory
x_refsource_SECUNIA
20231
third-party-advisory
x_refsource_SECUNIA
20653
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:030
vendor-advisory
x_refsource_SUSE
21749
third-party-advisory
x_refsource_SECUNIA
25731
vdb-entry
x_refsource_OSVDB
20782
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0526
vendor-advisory
x_refsource_REDHAT
2006-0032
vendor-advisory
x_refsource_TRUSTIX
ADV-2006-1941
vdb-entry
x_refsource_VUPEN
20232
third-party-advisory
x_refsource_SECUNIA
USN-288-1
vendor-advisory
x_refsource_UBUNTU
MDKSA-2006:098
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2006:021
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:9947
vdb-entry
signature
x_refsource_OVAL
20555
third-party-advisory
x_refsource_SECUNIA
1016142
vdb-entry
x_refsource_SECTRACK
USN-288-3
vendor-advisory
x_refsource_UBUNTU
USN-288-2
vendor-advisory
x_refsource_UBUNTU
20314
third-party-advisory
x_refsource_SECUNIA
DSA-1087
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now