Security Advisories (2)
CVE-2009-1341 (2009-04-30)

Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.

CVE-2012-1151 (2012-09-09)

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

Changes for version 0.93

  • it is required now to set the environment variables POSTGRES_INCLUDE and POSTGRES_LIB for compiling the module.
  • add Win32 port from Bob Kline <bkline@rksystems.com>.
  • support for all large-object functions via the func interface.
  • fixed bug with placeholders and casts spotted by mschout@gkg.net
  • replaced the method attributes by the method table_attributes, from Scott Williams <scott@james.com>.
  • fix type defintions for type_info_all(). bug spotted by "carlos" <emarcet@intramed.net.ar>.
  • now the Pg-specific quote() method also evaluates the data-type paramater.

Documentation

PostgreSQL database driver for the DBI module

Modules

PostgreSQL database driver for the DBI module

Provides

in Pg.pm
in Pg.pm
in Pg.pm

Examples