The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.
CVSS Details
- CVSS 3.1 Base Score: 4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/postgresql. | Oct 30, 2017 | May 3, 2005 |
| Suse | — | Upgrade postgresql-libsUpgrade postgresql-serverUpgrade postgresql-contribUpgrade postgresql-docsUpgrade postgresql-develUpgrade postgresql-libs-64bitUpgrade postgresqlUpgrade postgresql-plUpgrade postgresql-libs-32bitUpgrade postgresql-libs-x86 | Feb 17, 2015 | May 3, 2005 |
| Ubuntu | — | Upgrade postgresql | Nov 8, 2024 | May 3, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub