PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for “SELECT ST_AsX3D(‘LINESTRING EMPTY’);” because empty geometries are mishandled.
CPE | Name | Operator | Version |
---|---|---|---|
debian_linux | eq | 8.0 | |
debian_linux | eq | 9.0 | |
postgis | ge | 2.0.0 | |
postgis | lt | 2.3.3 |