Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59687
Category:Fedora Local Security Checks
Title:Fedora Core 7 FEDORA-2007-0249 (php-pear-DB)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to php-pear-DB
announced via advisory FEDORA-2007-0249.

DB is a database abstraction layer providing:
* an OO-style query API
* portability features that make programs written for one DBMS work with
other DBMS's
* a DSN (data source name) format for specifying database servers
* prepare/execute (bind) emulation for databases that don't support it natively
* a result object for each query response
* portable error codes
* sequence emulation
* sequential and non-sequential row fetching as well as bulk fetching
* formats fetched rows as associative arrays, ordered arrays or objects
* row limit support
* transactions support
* table information interface
* DocBook and phpDocumentor API documentation

DB layers itself on top of PHP's existing database extensions.

Update Information:

1.7.11 : fbsql:
* Fixed commit and rollback to specify the handle to be used.

* Mon Apr 30 2007 Remi Collet 1.7.11-1
- update to 1.7.11
- add generated CHANGELOG
References:

[ 1 ] CVE-2006-2313
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2313
[ 2 ] CVE-2006-2314
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2314
Updated packages:

Solution: Apply the appropriate updates.

This update can be installed with the 'yum' update program. Use 'yum update
package-name' at the command line. For more information, refer to 'Managing
Software with yum,' available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-0249

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-2313
BugTraq ID: 18092
http://www.securityfocus.com/bid/18092
Bugtraq: 20060523 PostgreSQL security releases 8.1.4, 8.0.8, 7.4.13, 7.3.15 (Google Search)
http://www.securityfocus.com/archive/1/435038/100/0/threaded
Bugtraq: 20060524 rPSA-2006-0080-1 postgresql postgresql-server (Google Search)
http://www.securityfocus.com/archive/1/435161/100/0/threaded
Debian Security Information: DSA-1087 (Google Search)
http://www.debian.org/security/2006/dsa-1087
http://security.gentoo.org/glsa/glsa-200607-04.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:098
http://archives.postgresql.org/pgsql-announce/2006-05/msg00010.php
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10618
http://www.redhat.com/support/errata/RHSA-2006-0526.html
http://securitytracker.com/id?1016142
http://secunia.com/advisories/20231
http://secunia.com/advisories/20232
http://secunia.com/advisories/20314
http://secunia.com/advisories/20435
http://secunia.com/advisories/20451
http://secunia.com/advisories/20503
http://secunia.com/advisories/20555
http://secunia.com/advisories/20653
http://secunia.com/advisories/20782
http://secunia.com/advisories/21001
SGI Security Advisory: 20060602-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
SuSE Security Announcement: SUSE-SA:2006:030 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0002.html
http://www.trustix.org/errata/2006/0032/
https://usn.ubuntu.com/288-1/
http://www.ubuntu.com/usn/usn-288-2
http://www.vupen.com/english/advisories/2006/1941
XForce ISS Database: postgresql-multibyte-sql-injection(26627)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26627
Common Vulnerability Exposure (CVE) ID: CVE-2006-2314
http://www.osvdb.org/25731
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9947
http://secunia.com/advisories/21749
SuSE Security Announcement: SUSE-SR:2006:021 (Google Search)
http://www.novell.com/linux/security/advisories/2006_21_sr.html
http://www.ubuntu.com/usn/usn-288-3
XForce ISS Database: postgresql-ascii-sql-injection(26628)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26628
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.