VDB
CVE-2005-0247
CVE-2005-0247
PUBLISHED
CVSS 6.5 MEDIUM
Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.
EPSS 3.51% · 88.1th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
3.51%
88.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| postgresql | postgresql | 7.2, 7.2.1, 7.2.2 |
Timeline
- Feb 8, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- May 31, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- RHSA-2005:138 vendor-advisory
- oval:org.mitre.oval:def:9345 vdb
- [pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser. mailing-list
- MDKSA-2005:040 vendor-advisory
- RHSA-2005:150 vendor-advisory
- 12417 vdb
- DSA-683 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-0247 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19375 url
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19376 url
- http://www.gentoo.org/security/en/glsa/glsa-200502-19.xml url
- http://www.novell.com/linux/security/advisories/2005_27_postgresql.html url
- http://www.novell.com/linux/security/advisories/2005_36_sudo.html url
- http://marc.info/?l=bugtraq&m=110806034116082&w=2 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19377 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19378 technical