English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 61204 CVE descriptions
and 32582 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60178
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 1460-1 (postgresql-8.1)
Summary:Debian Security Advisory DSA 1460-1 (postgresql-8.1)
Description:The remote host is missing an update to postgresql-8.1
announced via advisory DSA 1460-1.

Several local vulnerabilities have been discovered in PostgreSQL, an
object-relational SQL database. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2007-3278

It was discovered that the DBLink module performed insufficient
credential validation. This issue is also tracked as CVE-2007-6601,
since the initial upstream fix was incomplete.

CVE-2007-4769

Tavis Ormandy and Will Drewry discovered that a bug in the handling
of back-references inside the regular expressions engine could lead
to an out of bands read, resulting in a crash. This constitutes only
a security problem if an application using ProgreSQL processes
regular expressions from untrusted sources.

CVE-2007-4772

Tavis Ormandy and Will Drewry discovered that the optimizer for regular
expression could be tricked into an infinite loop, resulting in denial
of service. This constitutes only a security problem if an application
using ProgreSQL processes regular expressions from untrusted sources.

CVE-2007-6067

Tavis Ormandy and Will Drewry discovered that the optimizer for regular
expression could be tricked massive ressource consumption. This
constitutes only a security problem if an application using ProgreSQL
processes regular expressions from untrusted sources.

CVE-2007-6600

Functions in index expressions could lead to privilege escalation. For
a more in depth explanation please see the upstream announce available
at http://www.postgresql.org/about/news.905.

For the unstable distribution (sid), these problems have been fixed in
version 8.2.6-1 of postgresql-8.2.

For the stable distribution (etch), these problems have been fixed in version
postgresql-8.1 8.1.11-0etch1.

The old stable distribution (sarge), doesn't contain postgresql-8.1.

We recommend that you upgrade your postgresql-8.1 (8.1.11-0etch1) package.

Solution:
http://www.securityspace.com/smysecure/catid.html?in=DSA%201460-1
Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-3278
Bugtraq: 20070616 Having Fun With PostgreSQL (Google Search)
http://www.securityfocus.com/archive/1/archive/1/471541/100/0/threaded
Bugtraq: 20070618 Re: Having Fun With PostgreSQL (Google Search)
http://www.securityfocus.com/archive/1/471644/100/0/threaded
http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt
http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf
Debian Security Information: DSA-1460 (Google Search)
http://www.debian.org/security/2008/dsa-1460
Debian Security Information: DSA-1463 (Google Search)
http://www.debian.org/security/2008/dsa-1463
http://security.gentoo.org/glsa/glsa-200801-15.xml
HPdes Security Advisory: HPSBTU02325
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154
HPdes Security Advisory: SSRT080006
http://www.mandriva.com/security/advisories?name=MDKSA-2007:188
http://www.redhat.com/support/errata/RHSA-2008-0038.html
http://www.redhat.com/support/errata/RHSA-2008-0039.html
http://www.redhat.com/support/errata/RHSA-2008-0040.html
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1
http://www.ubuntulinux.org/support/documentation/usn/usn-568-1
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10334
http://www.vupen.com/english/advisories/2008/0109
http://www.vupen.com/english/advisories/2008/1071/references
http://osvdb.org/40899
http://secunia.com/advisories/28376
http://secunia.com/advisories/28438
http://secunia.com/advisories/28445
http://secunia.com/advisories/28437
http://secunia.com/advisories/28454
http://secunia.com/advisories/28477
http://secunia.com/advisories/28479
http://secunia.com/advisories/28679
http://secunia.com/advisories/29638
XForce ISS Database: postgresql-dblink-sql-injection(35142)
http://xforce.iss.net/xforce/xfdb/35142
Common Vulnerability Exposure (CVE) ID: CVE-2007-4769
Bugtraq: 20080107 PostgreSQL 2007-01-07 Cumulative Security Release (Google Search)
http://www.securityfocus.com/archive/1/archive/1/485864/100/0/threaded
Bugtraq: 20080115 rPSA-2008-0016-1 postgresql postgresql-server (Google Search)
http://www.securityfocus.com/archive/1/archive/1/486407/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:004
SuSE Security Announcement: SUSE-SA:2008:005 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html
BugTraq ID: 27163
http://www.securityfocus.com/bid/27163
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9804
http://www.vupen.com/english/advisories/2008/0061
http://securitytracker.com/id?1019157
http://secunia.com/advisories/28359
http://secunia.com/advisories/28464
http://secunia.com/advisories/28455
http://secunia.com/advisories/28698
XForce ISS Database: postgresql-backref-dos(39499)
http://xforce.iss.net/xforce/xfdb/39499
Common Vulnerability Exposure (CVE) ID: CVE-2007-4772
Bugtraq: 20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues (Google Search)
http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded
http://www.mandriva.com/security/advisories?name=MDVSA-2008:059
http://www.redhat.com/support/errata/RHSA-2008-0134.html
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11569
http://www.vupen.com/english/advisories/2008/1744
http://secunia.com/advisories/29070
http://secunia.com/advisories/29248
http://secunia.com/advisories/30535
XForce ISS Database: postgresql-regular-expression-dos(39497)
http://xforce.iss.net/xforce/xfdb/39497
Common Vulnerability Exposure (CVE) ID: CVE-2007-6067
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10235
XForce ISS Database: postgresql-complex-expression-dos(39498)
http://xforce.iss.net/xforce/xfdb/39498
Common Vulnerability Exposure (CVE) ID: CVE-2007-6600
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10493
XForce ISS Database: postgresql-indexfunctions-priv-escalation(39496)
http://xforce.iss.net/xforce/xfdb/39496
Common Vulnerability Exposure (CVE) ID: CVE-2007-6601
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11127
XForce ISS Database: postgresql-dblink-privilege-escalation(39500)
http://xforce.iss.net/xforce/xfdb/39500
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2014 E-Soft Inc. All rights reserved.