CVE-2005-1410

Description

The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as internal even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.1

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2005-1409,CVE-2005-1410 are affected in Postgresql 8.0.2Windows
Vulnerabilities CVE-2005-1410,CVE-2005-1409 are fixed in PostgreSQL 8.0.3Windows
Vulnerabilities CVE-2005-1410,CVE-2005-1409,CVE-2005-0247 are fixed in PostgreSQL 7.4.8Windows
Vulnerability CVE-2005-1409,CVE-2005-1410 are affected in Postgresql 8.0.2 (For Linux)Linux
Vulnerabilities CVE-2005-1410,CVE-2005-1409 are fixed in PostgreSQL 8.0.3 (For Linux)Linux
Vulnerabilities CVE-2005-1410,CVE-2005-1409,CVE-2005-0247 are fixed in PostgreSQL 7.4.8 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234