CVE-2009-2940

Description

The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.576

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2009-2940 are fixed in Python-pygresql 4.1Windows
Vulnerabilities CVE-2009-2940 are affected in Python-pygresql 3.8.1Windows
Vulnerabilities CVE-2009-2940 are fixed in Python-pygresql for linux 4.1Linux
Vulnerabilities CVE-2009-2940 are affected in Python-pygresql for linux 3.8.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234