[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2008:004 -- Mandriva postgresql

ID: oval:org.secpod.oval:def:301295Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




Index Functions Privilege Escalation : as a unique feature, PostgreSQL allows users to create indexes on the results of user-defined functions, known as expression indexes. This provided two vulnerabilities to privilege escalation: index functions were executed as the superuser and not the table owner during VACUUM and ANALYZE, and that SET ROLE and SET SESSION AUTHORIZATION were permitted within index functions. Regular Expression Denial-of-Service : three separate issues in the regular expression libraries used by PostgreSQL allowed malicious users to initiate a denial-of-service by passing certain regular expressions in SQL queries. First, users could create infinite loops using some specific regular expressions. Second, certain complex regular expressions could consume excessive amounts of memory. Third, out-of-range backref numbers could be used to crash the backend. DBLink Privilege Escalation : DBLink functions combined with local trust or ident authentication could be used by a malicious user to gain superuser privileges. This issue has been fixed, and does not affect users who have not installed DBLink , or who are using password authentication for local access. This same problem was addressed in the previous release cycle , but that patch failed to close all forms of the loophole. Updated packages fix these issues by upgrading to the latest maintenance versions of PostgreSQL.

Platform:
Mandriva Linux 2007.0
Mandriva Linux 2007.1
Mandriva Linux 2008.0
Product:
postgresql
Reference:
MDVSA-2008:004
CVE-2007-4769
CVE-2007-4772
CVE-2007-6067
CVE-2007-6600
CVE-2007-6601
CVE    5
CVE-2007-4769
CVE-2007-4772
CVE-2007-6600
CVE-2007-6601
...
CPE    3
cpe:/o:mandriva:linux:2007.1
cpe:/o:mandriva:linux:2008.0
cpe:/o:mandriva:linux:2007.0

© SecPod Technologies