CVE-2009-2940
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
El módulo pygresql v3.8.1 y v4.0 para Python no soporta de forma adecuada la función PQescapeStringConn, lo que podría permitir a atacantes remotos aprovechas cuestiones de escape incluidas en las codificaciones de carácter multibyte.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-08-23 CVE Reserved
- 2009-10-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/37654 | Third Party Advisory | |
http://www.osvdb.org/59028 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/37046 | 2009-12-19 | |
http://ubuntu.com/usn/usn-870-1 | 2009-12-19 | |
http://www.debian.org/security/2009/dsa-1911 | 2009-12-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pygresql Search vendor "Pygresql" | Pygresql Search vendor "Pygresql" for product "Pygresql" | 3.8.1 Search vendor "Pygresql" for product "Pygresql" and version "3.8.1" | - |
Affected
| in | Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | * | - |
Safe
|
Pygresql Search vendor "Pygresql" | Pygresql Search vendor "Pygresql" for product "Pygresql" | 4.0 Search vendor "Pygresql" for product "Pygresql" and version "4.0" | - |
Affected
| in | Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | * | - |
Safe
|