Candidate: CVE-2009-2943 PublicDate: 2009-10-22 16:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2943 Description: The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_postgresql-ocaml: upstream_postgresql-ocaml: released (1.12.1-2) dapper_postgresql-ocaml: ignored (reached end-of-life) hardy_postgresql-ocaml: ignored (reached end-of-life) intrepid_postgresql-ocaml: released (1.7.0-3+lenny1build0.8.10.1) jaunty_postgresql-ocaml: released (1.7.0-3+lenny1build0.9.04.1) karmic_postgresql-ocaml: ignored (reached end-of-life) lucid_postgresql-ocaml: not-affected (1.12.1-2) maverick_postgresql-ocaml: not-affected (1.12.1-2) natty_postgresql-ocaml: not-affected (1.12.1-2) oneiric_postgresql-ocaml: not-affected (1.12.1-2) devel_postgresql-ocaml: not-affected (1.12.1-2)