Description
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Email Template Designer-WP HTML Mail Cross-Site Scripting (3.0.9)
Java Unspesificed Vulnerability (CVE-2019-2818)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5478)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4792)