perl-DBD-Pg: Format string flaws by turning db notices into Perl warnings and by preparing DBD statement
Published Sep 9, 2012
5.0
MEDIUMCVSS 2.0
EPSS 2.74%
Description
Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.
Affected products
No data.
- ≤ 2.18.1
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.52
- 0.61
- 0.62
- 0.63
- 0.64
- 0.65
- 0.66
- 0.67
- 0.68
- 0.69
- 0.70
- 0.71
- 0.72
- 0.73
- 0.80
- 0.81
- 0.82
- 0.83
- 0.84
- 0.85
- 0.86
- 0.87
- 0.88
- 0.89
- 0.90
- 0.91
- 0.92
- 0.93
- 0.94
- 0.95
- 0.96
- 0.97
- 0.98
- 0.99
- 1.00
- 1.01
- 1.20
- 1.21
- 1.22
- 1.31
- 1.32
- 1.40
- 1.41
- 1.42
- 1.43
- 1.44
- 1.45
- 1.46
- 1.47
- 1.48
- 1.49
- 2.0.0
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.4.0
- 2.5.0
- 2.5.1
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.4
- 2.6.5
- 2.6.6
- 2.7.0
- 2.7.1
- 2.7.2
- 2.8.0
- 2.8.1
- 2.8.2
- 2.8.3
- 2.8.4
- 2.8.5
- 2.8.6
- 2.8.7
- 2.8.8
- 2.9.0
- 2.9.1
- 2.9.2
- 2.10.0
- 2.10.1
- 2.10.2
- 2.10.3
- 2.10.4
- 2.10.5
- 2.10.6
- 2.10.7
- 2.11.0
- 2.11.1
- 2.11.2
- 2.11.3
- 2.11.4
- 2.11.5
- 2.11.6
- 2.11.7
- 2.11.8
- 2.12.0
- 2.13.0
- 2.14.0
- 2.14.1
- 2.15.0
- 2.15.1
- 2.16.0
- 2.16.1
- 2.17.0
- 2.17.1
- 2.17.2
- 2.18.0
No data.
Red Hat Enterprise Linux 5
perl-DBD-Pg-0:1.49-4.el5_8
Fixed · RHSA-2012:1116
Red Hat Enterprise Linux 6
perl-DBD-Pg-0:2.15.1-4.el6_3
Fixed · RHSA-2012:1116
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | perl-DBD-Pg-0:1.49-4.el5_8 | Fixed | RHSA-2012:1116 |
| Red Hat Enterprise Linux 6 | perl-DBD-Pg-0:2.15.1-4.el6_3 | Fixed | RHSA-2012:1116 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.74% (0.02744) | 85.65th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.69% (0.02692) | 83.89th | v5 (v2026.06.15) |
| Mar 30, 2025 | 2.48% (0.02485) | 83.91th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.72% (0.03723) | 79.72th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.28% (0.02280) | 83.51th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.88% (0.02878) | 91.12th | v3 (v2023.03.01) |
| Oct 4, 2023 | 2.88% (0.02878) | 89.54th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.75% (0.02748) | 88.92th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
References (18)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=661536 x_refsource_MISC
- http://cpansearch.perl.org/src/TURNSTEP/DBD-Pg-2.19.1/Changes x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2012-1116.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/48307 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/48319 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/48824 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201204-08.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2012/dsa-2431 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:112 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2012/03/09/6 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/03/10/4 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2012-1151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=801733 x_refsource_MISCIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73854 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73855 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2012-1151
- https://rt.cpan.org/Public/Bug/Display.html?id=75642 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2012-1151
Change history (0)
No recorded changes yet.