First published: Thu Oct 22 2009(Updated: )
The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ocaml Postgresql-ocaml | =1.5.4 | |
Ocaml Postgresql-ocaml | =1.7.0 | |
Ocaml Postgresql-ocaml | =1.12.1 | |
PostgreSQL PostgreSQL |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.