Back to search
CVE-2012-1151
Published: Sep 9, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
MDVSA-2012:112
vendor-advisory
x_refsource_MANDRIVA
dbdpg-pgwarn-format-string(73854)
vdb-entry
x_refsource_XF
48307
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:1116
vendor-advisory
x_refsource_REDHAT
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=661536
x_refsource_MISC
http://cpansearch.perl.org/src/TURNSTEP/DBD-Pg-2.19.1/Changes
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=801733
x_refsource_MISC
48319
third-party-advisory
x_refsource_SECUNIA
dbdpg-dbdstprepare-format-string(73855)
vdb-entry
x_refsource_XF
GLSA-201204-08
vendor-advisory
x_refsource_GENTOO
DSA-2431
vendor-advisory
x_refsource_DEBIAN
48824
third-party-advisory
x_refsource_SECUNIA
https://rt.cpan.org/Public/Bug/Display.html?id=75642
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now