CVE-2005-1409

PostgreSQL 7.3.x-8.0.x - Unauthenticated Character Conversion Function Execution

Title source: llm
STIX 2.1

Description

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A676
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-433.html
Third Party Advisory, VDB Entry vendor-advisory x_refsource_fedora
http://www.securityfocus.com/archive/1/426302/30/6680/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0453
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13476
Patch x_refsource_confirm
http://www.postgresql.org/about/news.315
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10050
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_36_sudo.html

Scores

EPSS 0.0148
EPSS Percentile 81.2%

Details

Status published
Products (28)
postgresql/postgresql 7.2.1
postgresql/postgresql 7.2.2
postgresql/postgresql 7.2.3
postgresql/postgresql 7.2.4
postgresql/postgresql 7.2.5
postgresql/postgresql 7.2.6
postgresql/postgresql 7.2.7
postgresql/postgresql 7.3
postgresql/postgresql 7.3.1
postgresql/postgresql 7.3.2
... and 18 more
Published May 03, 2005
Tracked Since Feb 18, 2026