Vulnerability Name: | CVE-2009-0663 (CCN-50467) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2009-04-28 | ||||||||||||||||||||||||||||||||||||
Published: | 2009-04-28 | ||||||||||||||||||||||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||||||||||||||||||||||
Summary: | Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-0663 Source: SUSE Type: UNKNOWN SUSE-SR:2009:012 Source: CCN Type: Debian Web site Package libdbd-pg-perl Source: CCN Type: RHSA-2009-0479 Moderate: perl-DBD-Pg security update Source: CCN Type: RHSA-2009-1067 Moderate: Red Hat Application Stack v2.3 security and enhancement update Source: SECUNIA Type: UNKNOWN 34909 Source: SECUNIA Type: UNKNOWN 35058 Source: SECUNIA Type: UNKNOWN 35685 Source: CONFIRM Type: Patch http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz Source: CCN Type: ASA-2009-180 perl-DBD-Pg security update (RHSA-2009-0479) Source: CCN Type: ASA-2009-199 Red Hat Application Stack v2.3 security and enhancement update (RHSA-2009-1067) Source: DEBIAN Type: UNKNOWN DSA-1780 Source: DEBIAN Type: DSA-1780 libdbd-pg-perl -- several vulnerabilities Source: CCN Type: OSVDB ID: 54171 DBD::Pg Module for Perl Multiple Function Overflow Source: REDHAT Type: UNKNOWN RHSA-2009:0479 Source: REDHAT Type: UNKNOWN RHSA-2009:1067 Source: BID Type: UNKNOWN 34755 Source: CCN Type: BID-34755 DBD::Pg 'pg_getline()' and 'getline()' Heap Buffer Overflow Vulnerabilities Source: XF Type: UNKNOWN libdbdpgperl-unspecified-bo(50467) Source: XF Type: UNKNOWN libdbdpgperl-unspecified-bo(50467) Source: MISC Type: UNKNOWN https://launchpad.net/bugs/cve/2009-0663 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9499 Source: SUSE Type: SUSE-SR:2009:012 SUSE Security Summary Report | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |