CVE-2005-1409
Summary
| CVE | CVE-2005-1409 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-05-03 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability." |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 7.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.2.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.2.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.2.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 7.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IMPORTANT: two new PostgreSQL security problems found | af854a3a-2127-422b-91ae-364da2661108 | archives.postgresql.org | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PostgreSQL Character Set Conversion Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| PostgreSQL: News: SECURITY: Two New Problems Found | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.