The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-10-22T16:00:00

Updated: 2009-12-17T10:00:00

Reserved: 2009-08-23T00:00:00


Link: CVE-2009-2940

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-10-22T16:30:00.250

Modified: 2009-12-19T06:57:16.483


Link: CVE-2009-2940

JSON object: View

cve-icon Redhat Information

No data.