PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.
References
Link | Resource |
---|---|
https://lists.debian.org/debian-lts-announce/2019/01/msg00030.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/12/msg00020.html | Mailing List Third Party Advisory |
https://trac.osgeo.org/postgis/changeset/15444 | Patch Third Party Advisory |
https://trac.osgeo.org/postgis/changeset/15445 | Patch Third Party Advisory |
https://trac.osgeo.org/postgis/ticket/3704 | Exploit Third Party Advisory |
Configurations
History
06 Apr 2022, 18:33
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2019/01/msg00030.html - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2021/12/msg00020.html - Mailing List, Third Party Advisory | |
References | (MISC) https://trac.osgeo.org/postgis/ticket/3704 - Exploit, Third Party Advisory |
28 Dec 2021, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-01-25 05:29
Updated : 2024-02-04 20:03
NVD link : CVE-2017-18359
Mitre link : CVE-2017-18359
CVE.ORG link : CVE-2017-18359
JSON object : View
Products Affected
debian
- debian_linux
postgis
- postgis
CWE
CWE-20
Improper Input Validation