vulnerability
Ubuntu: (CVE-2017-18359): postgis vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Jan 25, 2019 | Nov 19, 2024 | Mar 27, 2026 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jan 25, 2019
Added
Nov 19, 2024
Modified
Mar 27, 2026
Description
PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.
Solution
ubuntu-upgrade-postgis
References
- CVE-2017-18359
- https://attackerkb.com/topics/CVE-2017-18359
- CWE-20
- EUVD-EUVD-2017-9478
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-9478
- https://trac.osgeo.org/postgis/changeset/15444
- https://trac.osgeo.org/postgis/changeset/15445
- https://trac.osgeo.org/postgis/ticket/3704
- https://www.cve.org/CVERecord?id=CVE-2017-18359
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.