Back
CVE-2005-0245
Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.
Published: Feb 1, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | * ≥ 7.3 < 7.3.10 |
| postgresql | postgresql | * ≥ 7.4 < 7.4.7 |
| postgresql | postgresql | 8.0 |
GitHub Security Advisory GHSA-8r34-wff9-3x69
Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute...
References (26)
- http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php Vendor Advisory
- http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php Vendor Advisory
- http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php Exploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=110806034116082&w=2 Issue Tracking, Third Party Advisory
- http://secunia.com/advisories/12948 Exploit, Patch, Vendor Advisory
- http://www.debian.org/security/2005/dsa-683 Exploit, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:040 Broken Link
- http://www.novell.com/linux/security/advisories/2005_36_sudo.html Broken Link
- http://www.redhat.com/support/errata/RHSA-2005-138.html Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-150.html Patch, Vendor Advisory
- http://www.securityfocus.com/bid/12417 Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19188 Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10175 Third Party Advisory
- http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php Vendor Advisory
- http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
14.47%
Top 4% most likely to be exploited
Threat Score
34.3 / 100
Data Sources
NVD
EPSS
GitHub