- Description
- backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via a coercion of an unknown element to ANYARRAY.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:N/I:N/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "617ED667-C8A3-49E3-BF54-56A6721C3AF2",
"versionEndExcluding": "7.4.14",
"versionStartIncluding": "7.4"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "973D7B2A-B63D-4D6A-88E1-598335690CC0",
"versionEndExcluding": "8.0.9",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E8994FC-90C5-469C-BF9F-8AE484C2F172",
"versionEndExcluding": "8.1.5",
"versionStartIncluding": "8.1.0"
}
],
"operator": "OR"
}
]
}
]