Vulnerability Name:

CVE-2009-1341 (CCN-50387)

Assigned:2009-04-28
Published:2009-04-28
Updated:2017-09-29
Summary:Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-200
CWE-401
Vulnerability Consequences:Denial of Service
References:Source: CONFIRM
Type: UNKNOWN
http://cpansearch.perl.org/src/TURNSTEP/DBD-Pg-2.13.1/Changes

Source: MITRE
Type: CNA
CVE-2009-1341

Source: SUSE
Type: UNKNOWN
SUSE-SR:2009:012

Source: CCN
Type: Debian Web site
Package libdbd-pg-perl

Source: CCN
Type: RHSA-2009-0479
Moderate: perl-DBD-Pg security update

Source: CCN
Type: RHSA-2009-1067
Moderate: Red Hat Application Stack v2.3 security and enhancement update

Source: CCN
Type: CPAN Bug #21392
Memory leak when fetching binary columns

Source: CONFIRM
Type: UNKNOWN
http://rt.cpan.org/Public/Bug/Display.html?id=21392

Source: SECUNIA
Type: Vendor Advisory
34909

Source: SECUNIA
Type: Vendor Advisory
35058

Source: SECUNIA
Type: UNKNOWN
35685

Source: CONFIRM
Type: UNKNOWN
http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz

Source: CCN
Type: ASA-2009-180
perl-DBD-Pg security update (RHSA-2009-0479)

Source: CCN
Type: ASA-2009-199
Red Hat Application Stack v2.3 security and enhancement update (RHSA-2009-1067)

Source: DEBIAN
Type: UNKNOWN
DSA-1780

Source: DEBIAN
Type: DSA-1780
libdbd-pg-perl -- several vulnerabilities

Source: CCN
Type: OSVDB ID: 54176
DBD::Pg Module for Perl quote.c dequote_bytea Function Memory Consumption DoS

Source: REDHAT
Type: UNKNOWN
RHSA-2009:0479

Source: REDHAT
Type: UNKNOWN
RHSA-2009:1067

Source: BID
Type: UNKNOWN
34757

Source: CCN
Type: BID-34757
DBD::Pg BYTEA Values Memory Leak Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
libdbdpgperl-dequotebytea-dos(50387)

Source: XF
Type: UNKNOWN
libdbdpgperl-dequotebytea-dos(50387)

Source: MISC
Type: UNKNOWN
https://launchpad.net/bugs/cve/2009-1341

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:9680

Source: SUSE
Type: SUSE-SR:2009:012
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:debian:libdbd-pg-perl:0.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.4:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.51:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.52:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.61:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.62:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.63:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.64:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.65:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.66:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.67:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.68:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.69:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.70:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.71:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.72:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.73:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.80:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.81:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.82:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.83:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.84:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.85:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.86:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.87:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.88:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.89:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.90:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.91:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.92:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.93:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.94:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.95:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.96:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.97:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.98:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.99:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:*:*:*:*:*:*:*:* (Version <= 1.4.9)

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:debian:libdbd-pg-perl:1.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.99:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.98:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.97:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.96:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.95:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.93:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.92:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.91:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.90:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.89:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.88:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.87:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.86:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.85:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.84:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.83:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.82:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.81:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.80:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.73:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.72:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.71:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.70:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.69:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.68:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.67:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.66:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.65:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.64:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.63:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.62:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.61:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.52:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.51:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.4:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:0.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:libdbd-pg-perl:1.4.9:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_application_stack:2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20091341
    V
    CVE-2009-1341
    2017-09-27
    oval:org.mitre.oval:def:29079
    P
    RHSA-2009:0479 -- perl-DBD-Pg security update (Moderate)
    2015-08-17
    oval:org.mitre.oval:def:13702
    P
    DSA-1780-1 libdbd-pg-perl -- several
    2014-06-23
    oval:org.mitre.oval:def:8139
    P
    DSA-1780 libdbd-pg-perl -- several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:22850
    P
    ELSA-2009:0479: perl-DBD-Pg security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:9680
    V
    Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.
    2013-04-29
    oval:com.redhat.rhsa:def:20090479
    P
    RHSA-2009:0479: perl-DBD-Pg security update (Moderate)
    2009-05-13
    oval:org.debian:def:1780
    V
    several vulnerabilities
    2009-04-28
    BACK
    debian libdbd-pg-perl 0.1
    debian libdbd-pg-perl 0.2
    debian libdbd-pg-perl 0.3
    debian libdbd-pg-perl 0.4
    debian libdbd-pg-perl 0.5
    debian libdbd-pg-perl 0.51
    debian libdbd-pg-perl 0.52
    debian libdbd-pg-perl 0.61
    debian libdbd-pg-perl 0.62
    debian libdbd-pg-perl 0.63
    debian libdbd-pg-perl 0.64
    debian libdbd-pg-perl 0.65
    debian libdbd-pg-perl 0.66
    debian libdbd-pg-perl 0.67
    debian libdbd-pg-perl 0.68
    debian libdbd-pg-perl 0.69
    debian libdbd-pg-perl 0.70
    debian libdbd-pg-perl 0.71
    debian libdbd-pg-perl 0.72
    debian libdbd-pg-perl 0.73
    debian libdbd-pg-perl 0.80
    debian libdbd-pg-perl 0.81
    debian libdbd-pg-perl 0.82
    debian libdbd-pg-perl 0.83
    debian libdbd-pg-perl 0.84
    debian libdbd-pg-perl 0.85
    debian libdbd-pg-perl 0.86
    debian libdbd-pg-perl 0.87
    debian libdbd-pg-perl 0.88
    debian libdbd-pg-perl 0.89
    debian libdbd-pg-perl 0.90
    debian libdbd-pg-perl 0.91
    debian libdbd-pg-perl 0.92
    debian libdbd-pg-perl 0.93
    debian libdbd-pg-perl 0.94
    debian libdbd-pg-perl 0.95
    debian libdbd-pg-perl 0.96
    debian libdbd-pg-perl 0.97
    debian libdbd-pg-perl 0.98
    debian libdbd-pg-perl 0.99
    debian libdbd-pg-perl 1.0.0
    debian libdbd-pg-perl 1.0.1
    debian libdbd-pg-perl 1.2.0
    debian libdbd-pg-perl 1.2.1
    debian libdbd-pg-perl 1.2.2
    debian libdbd-pg-perl 1.3.1
    debian libdbd-pg-perl 1.3.2
    debian libdbd-pg-perl 1.4.0
    debian libdbd-pg-perl 1.4.1
    debian libdbd-pg-perl 1.4.2
    debian libdbd-pg-perl 1.4.3
    debian libdbd-pg-perl 1.4.4
    debian libdbd-pg-perl 1.4.5
    debian libdbd-pg-perl 1.4.6
    debian libdbd-pg-perl 1.4.7
    debian libdbd-pg-perl 1.4.8
    debian libdbd-pg-perl *
    debian libdbd-pg-perl 1.4.8
    debian libdbd-pg-perl 1.4.7
    debian libdbd-pg-perl 1.4.6
    debian libdbd-pg-perl 1.4.5
    debian libdbd-pg-perl 1.4.4
    debian libdbd-pg-perl 1.4.3
    debian libdbd-pg-perl 1.4.2
    debian libdbd-pg-perl 1.4.1
    debian libdbd-pg-perl 1.4.0
    debian libdbd-pg-perl 1.3.2
    debian libdbd-pg-perl 1.3.1
    debian libdbd-pg-perl 1.2.2
    debian libdbd-pg-perl 1.2.1
    debian libdbd-pg-perl 1.2.0
    debian libdbd-pg-perl 1.0.1
    debian libdbd-pg-perl 1.0.0
    debian libdbd-pg-perl 0.99
    debian libdbd-pg-perl 0.98
    debian libdbd-pg-perl 0.97
    debian libdbd-pg-perl 0.96
    debian libdbd-pg-perl 0.95
    debian libdbd-pg-perl 0.93
    debian libdbd-pg-perl 0.92
    debian libdbd-pg-perl 0.91
    debian libdbd-pg-perl 0.90
    debian libdbd-pg-perl 0.89
    debian libdbd-pg-perl 0.88
    debian libdbd-pg-perl 0.87
    debian libdbd-pg-perl 0.86
    debian libdbd-pg-perl 0.85
    debian libdbd-pg-perl 0.84
    debian libdbd-pg-perl 0.83
    debian libdbd-pg-perl 0.82
    debian libdbd-pg-perl 0.81
    debian libdbd-pg-perl 0.80
    debian libdbd-pg-perl 0.73
    debian libdbd-pg-perl 0.72
    debian libdbd-pg-perl 0.71
    debian libdbd-pg-perl 0.70
    debian libdbd-pg-perl 0.69
    debian libdbd-pg-perl 0.68
    debian libdbd-pg-perl 0.67
    debian libdbd-pg-perl 0.66
    debian libdbd-pg-perl 0.65
    debian libdbd-pg-perl 0.64
    debian libdbd-pg-perl 0.63
    debian libdbd-pg-perl 0.62
    debian libdbd-pg-perl 0.61
    debian libdbd-pg-perl 0.52
    debian libdbd-pg-perl 0.51
    debian libdbd-pg-perl 0.5
    debian libdbd-pg-perl 0.4
    debian libdbd-pg-perl 0.3
    debian libdbd-pg-perl 0.2
    debian libdbd-pg-perl 0.1
    debian libdbd-pg-perl 1.4.9
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2008.0
    debian debian linux 4.0
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2008.0
    redhat rhel application stack 2