Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.871065
Category:Red Hat Local Security Checks
Title:RedHat Update for postgresql and postgresql84 RHSA-2013:1475-01
Summary:The remote host is missing an update for the 'postgresql and postgresql84'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'postgresql and postgresql84'
package(s) announced via the referenced advisory.

Vulnerability Insight:
PostgreSQL is an advanced object-relational database management system
(DBMS).

An array index error, leading to a heap-based out-of-bounds buffer read
flaw, was found in the way PostgreSQL performed certain error processing
using enumeration types. An unprivileged database user could issue a
specially crafted SQL query that, when processed by the server component of
the PostgreSQL service, would lead to a denial of service (daemon crash) or
disclosure of certain portions of server memory. (CVE-2013-0255)

A flaw was found in the way the pgcrypto contrib module of PostgreSQL
(re)initialized its internal random number generator. This could lead to
random numbers with less bits of entropy being used by certain pgcrypto
functions, possibly allowing an attacker to conduct other attacks.
(CVE-2013-1900)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Sumit Soni via Secunia SVCRP as the original
reporter of CVE-2013-0255, and Marko Kreen as the original reporter of
CVE-2013-1900.

These updated packages upgrade PostgreSQL to version 8.4.18, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes.

After installing this update, it is advisable to rebuild, using the REINDEX
command, Generalized Search Tree (GiST) indexes that meet one or more of
the following conditions:

- - GiST indexes on box, polygon, circle, or point columns

- - GiST indexes for variable-width data types, that is text, bytea, bit, and
numeric

- - GiST multi-column indexes

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.

Affected Software/OS:
postgresql and postgresql84 on Red Hat Enterprise Linux (v. 5 server),
Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:M/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-0255
BugTraq ID: 57844
http://www.securityfocus.com/bid/57844
Debian Security Information: DSA-2630 (Google Search)
http://www.debian.org/security/2013/dsa-2630
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:142
http://osvdb.org/89935
RedHat Security Advisories: RHSA-2013:1475
http://rhn.redhat.com/errata/RHSA-2013-1475.html
http://securitytracker.com/id?1028092
http://secunia.com/advisories/51923
http://secunia.com/advisories/52819
SuSE Security Announcement: openSUSE-SU-2013:0318 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-02/msg00059.html
SuSE Security Announcement: openSUSE-SU-2013:0319 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-02/msg00060.html
http://www.ubuntu.com/usn/USN-1717-1
XForce ISS Database: postgresql-enumrecv-dos(81917)
https://exchange.xforce.ibmcloud.com/vulnerabilities/81917
Common Vulnerability Exposure (CVE) ID: CVE-2013-1900
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html
Debian Security Information: DSA-2657 (Google Search)
http://www.debian.org/security/2013/dsa-2657
Debian Security Information: DSA-2658 (Google Search)
http://www.debian.org/security/2013/dsa-2658
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html
SuSE Security Announcement: SUSE-SU-2013:0633 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html
SuSE Security Announcement: openSUSE-SU-2013:0627 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html
SuSE Security Announcement: openSUSE-SU-2013:0628 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html
SuSE Security Announcement: openSUSE-SU-2013:0635 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html
http://www.ubuntu.com/usn/USN-1789-1
CopyrightCopyright (c) 2013 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.