First published: Mon Mar 30 2015(Updated: )
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.10.5 | |
PHP PHP | <5.4.40 | |
PHP PHP | >=5.5.0<5.5.24 | |
PHP PHP | >=5.6.0<5.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.