Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-2314

Опубликовано: 24 мая 2006
Источник: ubuntu
Приоритет: untriaged
CVSS2: 7.5

Описание

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1.0.beta3-3ubuntu5.5
devel

released

1.0.3-3ubuntu1
edgy

released

1.0.rc2-1ubuntu2.2
feisty

released

1.0.rc17-1ubuntu2.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

4.60-3ubuntu3.1
edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.2.10-1ubuntu0.1
edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

edgy

not-affected

feisty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life, was needed
devel

DNE

edgy

released

7.4.13-4
feisty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

8.1.9-0ubuntu0.6.06
devel

released

8.1.8-1ubuntu3
edgy

released

8.1.9-0ubuntu0.6.10
feisty

released

8.1.8-1ubuntu3
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

8.2.5-1
edgy

DNE

feisty

released

8.2.4-0ubuntu0.7.04
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1.1.21-3ubuntu3
devel

released

1.1.21-3ubuntu3
edgy

released

1.1.21-3ubuntu3
feisty

released

1.1.21-3ubuntu3
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

2.0.5.1-1
edgy

released

2.0.5.1-1
feisty

released

2.0.5.1-1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

3.7-1ubuntu2
devel

released

3.7-1ubuntu2
edgy

released

3.7-1ubuntu2
feisty

released

3.7-1ubuntu2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.4.0-6ubuntu3
devel

released

2.4.0-6ubuntu3
edgy

released

2.4.0-6ubuntu3
feisty

released

2.4.0-6ubuntu3
upstream

needs-triage

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
около 20 лет назад

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

nvd
около 19 лет назад

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

debian
около 19 лет назад

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13 ...

github
около 3 лет назад

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

7.5 High

CVSS2