PostgreSQL String Pad Function Buffer Overflow Vulnerability
BID:5528
Info
PostgreSQL String Pad Function Buffer Overflow Vulnerability
| Bugtraq ID: | 5528 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0972 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 20 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery credited to Sir Mordred The Traitor <[email protected]>. |
| Vulnerable: |
PostgreSQL PostgreSQL 7.2.1 PostgreSQL PostgreSQL 7.2 PostgreSQL PostgreSQL 7.1.3 PostgreSQL PostgreSQL 7.1.2 PostgreSQL PostgreSQL 7.1.1 PostgreSQL PostgreSQL 7.1 PostgreSQL PostgreSQL 7.0.3 PostgreSQL PostgreSQL 7.0.2 PostgreSQL PostgreSQL 6.5.3 PostgreSQL PostgreSQL 6.3.2 |
| Not Vulnerable: |
PostgreSQL PostgreSQL 7.2.3 PostgreSQL PostgreSQL 7.2.2 |
Discussion
PostgreSQL String Pad Function Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for PostgreSQL. Reportedly, PostgreSQL doesn't properly handle overly large integer arguments given to the lpad() and rpad() funtions. The functions are lpad() and rpad() found in the file, src/backend/utils/adt/oracle_compat.c, and serve to pad an existing text string with another up to a given length.
This vulnerability only affects data bases that were created using special international encodings. For example, databases that were created using a 'UNICODE' encoding are vulnerable to this issue.
A buffer overflow vulnerability has been reported for PostgreSQL. Reportedly, PostgreSQL doesn't properly handle overly large integer arguments given to the lpad() and rpad() funtions. The functions are lpad() and rpad() found in the file, src/backend/utils/adt/oracle_compat.c, and serve to pad an existing text string with another up to a given length.
This vulnerability only affects data bases that were created using special international encodings. For example, databases that were created using a 'UNICODE' encoding are vulnerable to this issue.
Exploit / POC
PostgreSQL String Pad Function Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.