Security Advisories (2)
CVE-2012-1151 (2012-09-09)

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

CVE-2009-1341 (2009-04-30)

Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.

Changes for version 0.97

  • fix bug in connect method, which erroneously set the userid and the password to the environment variables DBI_USER and DBI_PASS.
  • applied patch from Jan-Pieter Cornet <john@pc.xs4all.nl>, which removed the special handling of a backslash when used for octal presentation. Now a backslash always will be escaped.

Documentation

PostgreSQL database driver for the DBI module

Modules

PostgreSQL database driver for the DBI module UNAUTHORIZED

Provides

in Pg.pm UNAUTHORIZED
in Pg.pm UNAUTHORIZED
in Pg.pm UNAUTHORIZED

Examples