PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/postgresql. | Oct 30, 2017 | May 3, 2005 |
| Suse | — | Upgrade postgresql-contribUpgrade postgresql-plUpgrade postgresql-libs-32bitUpgrade postgresql-develUpgrade postgresql-libsUpgrade postgresqlUpgrade postgresql-docsUpgrade postgresql-serverUpgrade postgresql-libs-64bitUpgrade postgresql-libs-x86 | Feb 17, 2015 | May 3, 2005 |
| Ubuntu | — | Upgrade postgresql | Nov 8, 2024 | May 3, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub