CVE-2012-1151

medium
Published 2012-09-09 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.19.0-1
debian debianbullseyefixed2.19.0-1
debian debianforkyfixed2.19.0-1
debian debiansidfixed2.19.0-1
debian debiantrixiefixed2.19.0-1

Application impact

VendorProductVersionsFixed
perlperl{"endIncluding":"2.18.1"}
perlperl0.1
perlperl0.2
perlperl0.3
perlperl0.4
perlperl0.5
perlperl0.52
perlperl0.61
perlperl0.62
perlperl0.63
perlperl0.64
perlperl0.65
perlperl0.66
perlperl0.67
perlperl0.68
perlperl0.69
perlperl0.70
perlperl0.71
perlperl0.72
perlperl0.73
perlperl0.80
perlperl0.81
perlperl0.82
perlperl0.83
perlperl0.84
perlperl0.85
perlperl0.86
perlperl0.87
perlperl0.88
perlperl0.89
perlperl0.90
perlperl0.91
perlperl0.92
perlperl0.93
perlperl0.94
perlperl0.95
perlperl0.96
perlperl0.97
perlperl0.98
perlperl0.99
perlperl1.00
perlperl1.01
perlperl1.20
perlperl1.21
perlperl1.22
perlperl1.31
perlperl1.32
perlperl1.40
perlperl1.41
perlperl1.42
perlperl1.43
perlperl1.44
perlperl1.45
perlperl1.46
perlperl1.47
perlperl1.48
perlperl1.49
perlperl2.0.0
perlperl2.1.0
perlperl2.1.1
perlperl2.1.2
perlperl2.1.3
perlperl2.2.0
perlperl2.2.1
perlperl2.2.2
perlperl2.3.0
perlperl2.4.0
perlperl2.5.0
perlperl2.5.1
perlperl2.6.0
perlperl2.6.1
perlperl2.6.2
perlperl2.6.3
perlperl2.6.4
perlperl2.6.5
perlperl2.6.6
perlperl2.7.0
perlperl2.7.1
perlperl2.7.2
perlperl2.8.0
perlperl2.8.1
perlperl2.8.2
perlperl2.8.3
perlperl2.8.4
perlperl2.8.5
perlperl2.8.6
perlperl2.8.7
perlperl2.8.8
perlperl2.9.0
perlperl2.9.1
perlperl2.9.2
perlperl2.10.0
perlperl2.10.1
perlperl2.10.2
perlperl2.10.3
perlperl2.10.4
perlperl2.10.5
perlperl2.10.6
perlperl2.10.7
perlperl2.11.0
perlperl2.11.1
perlperl2.11.2
perlperl2.11.3
perlperl2.11.4
perlperl2.11.5
perlperl2.11.6
perlperl2.11.7
perlperl2.11.8
perlperl2.12.0
perlperl2.13.0
perlperl2.14.0
perlperl2.14.1
perlperl2.15.0
perlperl2.15.1
perlperl2.16.0
perlperl2.16.1
perlperl2.17.0
perlperl2.17.1
perlperl2.17.2
perlperl2.18.0

References

CWEs

CWE-134

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.