PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty geometries are mishandled.
References
Link | Resource |
---|---|
https://trac.osgeo.org/postgis/ticket/3704 | Exploit Third Party Advisory |
https://trac.osgeo.org/postgis/changeset/15445 | Patch Third Party Advisory |
https://trac.osgeo.org/postgis/changeset/15444 | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2019/01/msg00030.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/12/msg00020.html | Mailing List Third Party Advisory |
Information
Published : 2019-01-24 21:29
Updated : 2022-04-06 11:33
NVD link : CVE-2017-18359
Mitre link : CVE-2017-18359
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
debian
- debian_linux
postgis
- postgis