CVE-2005-1410

6 documents6 sources
Severity
2.1LOW
EPSS
0.1%
top 68.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateMay 1

Description

The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-43pr-qcpc-578c: The tsearch2 module in PostgreSQL 72022-05-01
CVEList
CVE-2005-1410: The tsearch2 module in PostgreSQL 72005-05-03

📋Vendor Advisories

2
Ubuntu
PostgreSQL vulnerabilities2005-05-04
Red Hat
security flaw2005-05-02

💬Community

1
Bugzilla
CVE-2005-1410 security flaw2018-08-16