Description: | Description:
The remote host is missing updates announced in advisory RHSA-2007:0067.
PostgreSQL is an advanced Object-Relational database management system (DBMS).
Two flaws were found in the way the PostgreSQL server handles certain SQL-language functions. An authenticated user could execute a sequence of command which could crash the PostgreSQL server or possibly read from arbitrary memory locations. A user must have permissions to drop and add database tables to exploit this flaw. (CVE-2007-0555, CVE-2007-0556)
Several denial of service flaws were found in the PostgreSQL server. An authenticated user could execute an SQL command which could crash the PostgreSQL server. (CVE-2006-5540, CVE-2006-5541, CVE-2006-5542)
Users of PostgreSQL should upgrade to these updated packages containing PostgreSQL version 8.1.7, which corrects these issues.
Note: The original PostgreSQL 8.1.7 security patch contained an error this release includes the updated patch and so is equivalent to the soon-to-be-released 8.1.8.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2007-0067.html http://www.redhat.com/security/updates/classification/#moderate
Risk factor : Critical
CVSS Score: 8.5
|