CVE Database
/

CVE-2007-4639

Back to search

CVE-2007-4639

Published: Aug 31, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as demonstrated by (1) pldbg_get_stack and (2) pldbg_abort_target, which triggers use of an uninitialized pointer.

VendorProductVersions

n/a

n/a

affected
n/a

References

25481
vdb-entry
x_refsource_BID
ADV-2007-3040
vdb-entry
x_refsource_VUPEN
26640
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now