CVE-2006-5542: Medium severity PostgreSQL postgresql vulnerability
Published Oct 26, 2006
·Updated
backend/tcop/postgres.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) related to duration logging of V3-protocol Execute messages for (1) COMMIT and (2) ROLLBACK SQL statements.
Affected Software
5 affected components
PostgreSQL postgresql=8.1
PostgreSQL postgresql=8.1.1
PostgreSQL postgresql=8.1.2
PostgreSQL postgresql=8.1.3
PostgreSQL postgresql=8.1.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 26, 2006
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5542?
CVE-2006-5542 has a medium severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2006-5542?
To fix CVE-2006-5542, upgrade PostgreSQL to version 8.1.5 or later.
3
Who is affected by CVE-2006-5542?
CVE-2006-5542 affects PostgreSQL versions 8.1.x prior to 8.1.5.
4
What type of attack does CVE-2006-5542 enable?
CVE-2006-5542 enables remote authenticated users to crash the PostgreSQL daemon.
5
What SQL statements are involved in CVE-2006-5542?
CVE-2006-5542 involves the duration logging of COMMIT and ROLLBACK SQL statements.