CVE
- Id
- 18418
- CVE No.
- CVE-2006-2314
- Status
- Candidate
- Description
- PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.
- Phase
- Assigned (20060511)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
159860 | 18418 | CVE-2006-2314 | BUGTRAQ:20060523 PostgreSQL security releases 8.1.4, 8.0.8, 7.4.13, 7.3.15 | View |
159861 | 18418 | CVE-2006-2314 | URL:http://www.securityfocus.com/archive/1/archive/1/435038/100/0/threaded | View |
159862 | 18418 | CVE-2006-2314 | BUGTRAQ:20060524 rPSA-2006-0080-1 postgresql postgresql-server | View |
159863 | 18418 | CVE-2006-2314 | URL:http://www.securityfocus.com/archive/1/archive/1/435161/100/0/threaded | View |
159864 | 18418 | CVE-2006-2314 | MLIST:[pgsql-announce] 20060523 Security Releases for All Active Versions | View |
159865 | 18418 | CVE-2006-2314 | URL:http://archives.postgresql.org/pgsql-announce/2006-05/msg00010.php | View |
159866 | 18418 | CVE-2006-2314 | CONFIRM:http://www.postgresql.org/docs/techdocs.50 | View |
159867 | 18418 | CVE-2006-2314 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm | View |
159868 | 18418 | CVE-2006-2314 | DEBIAN:DSA-1087 | View |
159869 | 18418 | CVE-2006-2314 | URL:http://www.debian.org/security/2006/dsa-1087 | View |
159870 | 18418 | CVE-2006-2314 | GENTOO:GLSA-200607-04 | View |
159871 | 18418 | CVE-2006-2314 | URL:http://security.gentoo.org/glsa/glsa-200607-04.xml | View |
159872 | 18418 | CVE-2006-2314 | MANDRIVA:MDKSA-2006:098 | View |
159873 | 18418 | CVE-2006-2314 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:098 | View |
159874 | 18418 | CVE-2006-2314 | REDHAT:RHSA-2006:0526 | View |
159875 | 18418 | CVE-2006-2314 | URL:http://www.redhat.com/support/errata/RHSA-2006-0526.html | View |
159876 | 18418 | CVE-2006-2314 | SGI:20060602-01-U | View |
159877 | 18418 | CVE-2006-2314 | URL:ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc | View |
159878 | 18418 | CVE-2006-2314 | SUSE:SUSE-SA:2006:030 | View |
159879 | 18418 | CVE-2006-2314 | URL:http://lists.suse.com/archive/suse-security-announce/2006-Jun/0002.html | View |
159880 | 18418 | CVE-2006-2314 | SUSE:SUSE-SR:2006:021 | View |
159881 | 18418 | CVE-2006-2314 | URL:http://www.novell.com/linux/security/advisories/2006_21_sr.html | View |
159882 | 18418 | CVE-2006-2314 | TRUSTIX:2006-0032 | View |
159883 | 18418 | CVE-2006-2314 | URL:http://www.trustix.org/errata/2006/0032/ | View |
159884 | 18418 | CVE-2006-2314 | UBUNTU:USN-288-1 | View |
159885 | 18418 | CVE-2006-2314 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-288-1 | View |
159886 | 18418 | CVE-2006-2314 | UBUNTU:USN-288-2 | View |
159887 | 18418 | CVE-2006-2314 | URL:http://www.ubuntu.com/usn/usn-288-2 | View |
159888 | 18418 | CVE-2006-2314 | UBUNTU:USN-288-3 | View |
159889 | 18418 | CVE-2006-2314 | URL:http://www.ubuntu.com/usn/usn-288-3 | View |
159890 | 18418 | CVE-2006-2314 | BID:18092 | View |
159891 | 18418 | CVE-2006-2314 | URL:http://www.securityfocus.com/bid/18092 | View |
159892 | 18418 | CVE-2006-2314 | OVAL:oval:org.mitre.oval:def:9947 | View |
159893 | 18418 | CVE-2006-2314 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9947 | View |
159894 | 18418 | CVE-2006-2314 | VUPEN:ADV-2006-1941 | View |
159895 | 18418 | CVE-2006-2314 | URL:http://www.vupen.com/english/advisories/2006/1941 | View |
159896 | 18418 | CVE-2006-2314 | OSVDB:25731 | View |
159897 | 18418 | CVE-2006-2314 | URL:http://www.osvdb.org/25731 | View |
159898 | 18418 | CVE-2006-2314 | SECTRACK:1016142 | View |
159899 | 18418 | CVE-2006-2314 | URL:http://securitytracker.com/id?1016142 | View |
159900 | 18418 | CVE-2006-2314 | SECUNIA:20231 | View |
159901 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20231 | View |
159902 | 18418 | CVE-2006-2314 | SECUNIA:20232 | View |
159903 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20232 | View |
159904 | 18418 | CVE-2006-2314 | SECUNIA:20314 | View |
159905 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20314 | View |
159906 | 18418 | CVE-2006-2314 | SECUNIA:20435 | View |
159907 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20435 | View |
159908 | 18418 | CVE-2006-2314 | SECUNIA:20451 | View |
159909 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20451 | View |
159910 | 18418 | CVE-2006-2314 | SECUNIA:20503 | View |
159911 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20503 | View |
159912 | 18418 | CVE-2006-2314 | SECUNIA:20555 | View |
159913 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20555 | View |
159914 | 18418 | CVE-2006-2314 | SECUNIA:20782 | View |
159915 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20782 | View |
159916 | 18418 | CVE-2006-2314 | SECUNIA:21001 | View |
159917 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/21001 | View |
159918 | 18418 | CVE-2006-2314 | SECUNIA:21749 | View |
159919 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/21749 | View |
159920 | 18418 | CVE-2006-2314 | SECUNIA:20653 | View |
159921 | 18418 | CVE-2006-2314 | URL:http://secunia.com/advisories/20653 | View |
159922 | 18418 | CVE-2006-2314 | XF:postgresql-ascii-sql-injection(26628) | View |
159923 | 18418 | CVE-2006-2314 | URL:http://xforce.iss.net/xforce/xfdb/26628 | View |
159924 | 18418 | CVE-2006-2314 | XF:postgresql-multibyte-sql-injection(26627) | View |