Description: | Description:
The remote host is missing updates announced in advisory RHSA-2005:150.
PostgreSQL is an advanced Object-Relational database management system (DBMS).
A flaw in the LOAD command in PostgreSQL was discovered. A local user could use this flaw to load arbitrary shared libraries and therefore execute arbitrary code, gaining the privileges of the PostgreSQL server. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2005-0227 to this issue.
Multiple buffer overflows were found in PL/PgSQL. A database user who has permissions to create plpgsql functions could trigger this flaw which could lead to arbitrary code execution, gaining the privileges of the PostgreSQL server. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2005-0245 and CVE-2005-0247 to these issues.
Users of PostgreSQL are advised to update to these erratum packages which are not vulnerable to these issues.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2005-150.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0227 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0245 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0247
Risk factor : High
CVSS Score: 7.5
|