Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-1618
HistoryOct 06, 2012 - 12:00 a.m.

CVE-2012-1618

2012-10-0600:00:00
ubuntu.com
ubuntu.com
14

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.006 Low

EPSS

Percentile

79.0%

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with
a PostgreSQL server with the β€œstandard_conforming_strings” option enabled,
such as the default configuration of PostgreSQL 9.1, does not properly
escape unspecified JDBC statement parameters, which allows remote attackers
to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that
the upstream developer planned to dispute this issue, but an official
dispute has not been posted as of 20121005.

Bugs

Notes

Author Note
sbeattie according to comment 11 in novell bug 754273 (below), this was fixed in 8.2-504)

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.006 Low

EPSS

Percentile

79.0%