Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4qg-8m5f-3hcv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

EPSS

Процентиль: 95%
0.19528
Средний

Связанные уязвимости

ubuntu
около 10 лет назад

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

redhat
больше 10 лет назад

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

nvd
около 10 лет назад

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.

debian
около 10 лет назад

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) ...

CVSS3: 5.3
fstec
около 10 лет назад

Уязвимость функция build_tablename (pgsql.c) интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.19528
Средний