Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56367
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-258-1 (postgresql)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to postgresql
announced via advisory USN-258-1.

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected: postgresql postgresql-7.4 postgresql-8.0

Akio Ishida discovered that the SET SESSION AUTHORIZATION command did
not properly verify the validity of its argument. An authenticated
PostgreSQL user could exploit this to crash the server.

However, this does not affect the official binary Ubuntu packages. The
crash can only be triggered if the source package is rebuilt with
assertions enabled (which is not the case in the official binary
packages).

Solution:
The problem can be corrected by upgrading the affected package to
version 7.4.5-3ubuntu0.6 (for Ubuntu 4.10), 7.4.7-2ubuntu2.2 (for
Ubuntu 5.04), 8.0.3-15ubuntu2.1 (postgresql-8.0 for Ubuntu 5.10), or
1:7.4.8-17ubuntu1.1 (postgresql-7.4 for Ubuntu 5.10). In general, a
standard system upgrade is sufficient to effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-258-1

Risk factor : Low

CVSS Score:
1.5

Cross-Ref: BugTraq ID: 16650
Common Vulnerability Exposure (CVE) ID: CVE-2006-0678
http://www.securityfocus.com/bid/16650
Bugtraq: 20060215 PostgreSQL security releases 8.1.3, 8.0.7, 7.4.12, 7.3.14 (Google Search)
http://www.securityfocus.com/archive/1/425037/100/0/threaded
http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html
http://secunia.com/advisories/18890
http://secunia.com/advisories/19015
http://secunia.com/advisories/19035
http://securityreason.com/securityalert/498
http://www.trustix.org/errata/2006/0008
http://www.ubuntu.com/usn/usn-258-1
http://www.vupen.com/english/advisories/2006/0605
XForce ISS Database: postgresql-setsessionauth-dos(24719)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24719
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.