First published: Wed Oct 20 2004(Updated: )
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/postgresql | <7.5.16.1 | 7.5.16.1 |
ubuntu/postgresql | <7.5.16.1 | 7.5.16.1 |
ubuntu/postgresql-7.4 | <7.4.12-3 | 7.4.12-3 |
ubuntu/postgresql-7.4 | <7.4.12-3 | 7.4.12-3 |
ubuntu/postgresql-8.0 | <8.0.7-2 | 8.0.7-2 |
ubuntu/postgresql-8.1 | <8.1.9-0ubuntu0.6.06 | 8.1.9-0ubuntu0.6.06 |
ubuntu/postgresql-8.1 | <8.1.9-0ubuntu0.6.10 | 8.1.9-0ubuntu0.6.10 |
ubuntu/postgresql-8.1 | <8.1.8-1ubuntu3 | 8.1.8-1ubuntu3 |
ubuntu/postgresql-8.2 | <8.2.4-0ubuntu0.7.04 | 8.2.4-0ubuntu0.7.04 |
debian/postgresql | ||
PostgreSQL JDBC Driver | >=7.3.0<7.3.8 | |
PostgreSQL JDBC Driver | >=7.4.0<7.4.6 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =10.1 | |
Mandrake Linux | =10.1 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandriva Linux Corporate Server | =2.1 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =3.0 | |
redhat enterprise Linux desktop | =3.0 | |
Trustix Secure Linux | =2.0 | |
Trustix Secure Linux | =2.1 | |
PostgreSQL JDBC Driver | =7.4.3 | |
PostgreSQL JDBC Driver | =7.4.5 | |
PostgreSQL JDBC Driver | =7.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0977 has a moderate severity rating due to its potential for local file overwriting through symlink attacks.
To fix CVE-2004-0977, upgrade to PostgreSQL version 7.5.16.1 or later.
CVE-2004-0977 affects PostgreSQL versions 7.4.5 and earlier.
Yes, local users can exploit CVE-2004-0977 to overwrite files.
A direct workaround for CVE-2004-0977 is to restrict access to the affected script and its temporary files.