Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.51486
Kategorie:Conectiva Local Security Checks
Titel:Conectiva Security Advisory CLA-2003:784
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing updates announced in
advisory CLA-2003:784.

PostgreSQL[1] is a sophisticated relational database which supports
almost all SQL constructs, including subselects, transactions and
user-defined types and functions.

Guido Notari reported a buffer overflow vulnerability[2][3] in the
to_ascii() function that could possibly be used by attackers to
execute arbitrary code. This vulnerability was fixed by Tom Lane who,
later on, according to CVS changelogs[4], found another buffer
overflow problem in the same function which was also fixed.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.postgresql.com/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0901
http://www.securityfocus.com/bid/8741
http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c
http://www.securityspace.com/smysecure/catid.html?in=CLA-2003:784
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002003

Risk factor : High

CVSS Score:
7.5

Querverweis: BugTraq ID: 8741
Common Vulnerability Exposure (CVE) ID: CVE-2003-0901
http://www.securityfocus.com/bid/8741
Conectiva Linux advisory: CLA-2003:784
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000784
Conectiva Linux advisory: CLSA-2003:772
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000772
Debian Security Information: DSA-397 (Google Search)
http://www.debian.org/security/2003/dsa-397
http://www.redhat.com/support/errata/RHSA-2003-313.html
http://www.redhat.com/support/errata/RHSA-2003-314.html
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.