CVE-2005-1410
Gentoo Linux Security Advisory 200505-12
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.
PostgreSQL gives public EXECUTE access to a number of character conversion routines, but doesn't validate the given arguments (CVE-2005-1409). It has also been reported that the contrib/tsearch2 module of PostgreSQL misdeclares the return value of some functions as internal (CVE-2005-1410). Versions less than 8.0.2-r1 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2005-05-03 CVE Reserved
- 2005-05-03 CVE Published
- 2024-08-07 CVE Updated
- 2025-06-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (11)
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| http://archives.postgresql.org/pgsql-announce/2005-05/msg00001.php | 2018-10-19 | |
| http://www.postgresql.org/about/news.315 | 2018-10-19 | |
| http://www.securityfocus.com/bid/13475 | 2018-10-19 |
| URL | Date | SRC |
|---|---|---|
| http://www.novell.com/linux/security/advisories/2005_36_sudo.html | 2018-10-19 | |
| http://www.redhat.com/support/errata/RHSA-2005-433.html | 2018-10-19 | |
| http://www.securityfocus.com/archive/1/426302/30/6680/threaded | 2018-10-19 | |
| https://access.redhat.com/security/cve/CVE-2005-1410 | 2005-06-01 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1617633 | 2005-06-01 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 7.4 Search vendor "Postgresql" for product "Postgresql" and version "7.4" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 7.4.3 Search vendor "Postgresql" for product "Postgresql" and version "7.4.3" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 7.4.5 Search vendor "Postgresql" for product "Postgresql" and version "7.4.5" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 7.4.6 Search vendor "Postgresql" for product "Postgresql" and version "7.4.6" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 7.4.7 Search vendor "Postgresql" for product "Postgresql" and version "7.4.7" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 8.0 Search vendor "Postgresql" for product "Postgresql" and version "8.0" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 8.0.1 Search vendor "Postgresql" for product "Postgresql" and version "8.0.1" | - |
Affected
| ||||||
| Postgresql Search vendor "Postgresql" | Postgresql Search vendor "Postgresql" for product "Postgresql" | 8.0.2 Search vendor "Postgresql" for product "Postgresql" and version "8.0.2" | - |
Affected
| ||||||
| Trustix Search vendor "Trustix" | Secure Linux Search vendor "Trustix" for product "Secure Linux" | 2.0 Search vendor "Trustix" for product "Secure Linux" and version "2.0" | - |
Affected
| ||||||
