Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.58002
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2007:037 (postgresql)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to postgresql
announced via advisory MDKSA-2007:037.

Jeff Trout discovered that the PostgreSQL server did not sufficiently
check data types of SQL function arguments in some cases. A user could
then exploit this to crash the database server or read out arbitrary
locations of the server's memory, which could be used to retrieve
database contents that the user should not be able to see. Note that a
user must be authenticated in order to exploit this (CVE-2007-0555).

As well, Jeff Trout also discovered that the query planner did not
verify that a table was still compatible with a previously-generated
query plan, which could be exploted to read out arbitrary locations of
the server's memory by using ALTER COLUMN TYPE during query execution.
Again, a user must be authenticated in order to exploit this
(CVE-2007-0556).

Updated packages have been patched to correct these issues.

Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:037

Risk factor : Critical

CVSS Score:
8.5

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2007-0555
BugTraq ID: 22387
http://www.securityfocus.com/bid/22387
Bugtraq: 20070206 rPSA-2007-0025-1 postgresql postgresql-server (Google Search)
http://www.securityfocus.com/archive/1/459280/100/0/threaded
Bugtraq: 20070208 rPSA-2007-0025-2 postgresql postgresql-server (Google Search)
http://www.securityfocus.com/archive/1/459448/100/0/threaded
Debian Security Information: DSA-1261 (Google Search)
http://www.debian.org/security/2007/dsa-1261
http://fedoranews.org/cms/node/2554
http://security.gentoo.org/glsa/glsa-200703-15.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:037
http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html
http://osvdb.org/33087
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9739
http://www.redhat.com/support/errata/RHSA-2007-0064.html
http://www.redhat.com/support/errata/RHSA-2007-0067.html
http://www.redhat.com/support/errata/RHSA-2007-0068.html
http://securitytracker.com/id?1017597
http://secunia.com/advisories/24028
http://secunia.com/advisories/24033
http://secunia.com/advisories/24042
http://secunia.com/advisories/24050
http://secunia.com/advisories/24057
http://secunia.com/advisories/24094
http://secunia.com/advisories/24151
http://secunia.com/advisories/24158
http://secunia.com/advisories/24284
http://secunia.com/advisories/24315
http://secunia.com/advisories/24513
http://secunia.com/advisories/24577
http://secunia.com/advisories/25220
SGI Security Advisory: 20070201-01-P
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1
SuSE Security Announcement: SUSE-SR:2007:010 (Google Search)
http://www.novell.com/linux/security/advisories/2007_10_sr.html
http://www.trustix.org/errata/2007/0007
https://usn.ubuntu.com/417-1/
http://www.ubuntu.com/usn/usn-417-2
http://www.vupen.com/english/advisories/2007/0478
http://www.vupen.com/english/advisories/2007/0774
XForce ISS Database: postgresql-sqlfunctions-info-disclosure(32195)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32195
Common Vulnerability Exposure (CVE) ID: CVE-2007-0556
http://osvdb.org/33302
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11353
XForce ISS Database: postgresql-datatype-information-disclosure(32191)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32191
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.