The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
References
Link | Resource |
---|---|
http://secunia.com/advisories/37048 | Vendor Advisory |
http://www.debian.org/security/2009/dsa-1909 | Patch |
http://www.osvdb.org/59029 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:24:07
Updated: 2022-10-03T16:24:07
Reserved: 2022-10-03T00:00:00
Link: CVE-2009-2943
JSON object: View
NVD Information
Status : Analyzed
Published: 2009-10-22T16:30:00.297
Modified: 2009-10-23T04:00:00.000
Link: CVE-2009-2943
JSON object: View
Redhat Information
No data.
CWE