CVE-2006-5540: Medium severity PostgreSQL postgresql vulnerability
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimization."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5540?
CVE-2006-5540 is classified as a high severity vulnerability, as it can cause a denial of service through a daemon crash.
How do I fix CVE-2006-5540?
To fix CVE-2006-5540, you should upgrade PostgreSQL to version 8.1.5 or later.
Who is affected by CVE-2006-5540?
CVE-2006-5540 affects remote authenticated users of PostgreSQL versions 8.1.x before 8.1.5 and several earlier versions.
What types of attacks are associated with CVE-2006-5540?
CVE-2006-5540 allows attackers to exploit certain aggregate functions in UPDATE statements to crash the PostgreSQL daemon.
Is CVE-2006-5540 exploitable from a remote location?
Yes, CVE-2006-5540 can be exploited by remote authenticated users.