CVE-2007-4639: Code Injection
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbgcreatelistener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg function, as demonstrated by (1) pldbggetstack and (2) pldbgaborttarget, which triggers use of an uninitialized pointer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4639?
CVE-2007-4639 has a high severity rating as it allows for denial of service and potential arbitrary code execution.
How do I fix CVE-2007-4639?
To fix CVE-2007-4639, upgrade to a version of EnterpriseDB Advanced Server beyond 8.2 that addresses this vulnerability.
Who is affected by CVE-2007-4639?
CVE-2007-4639 affects users of EnterpriseDB Advanced Server version 8.2.
What attack vectors are associated with CVE-2007-4639?
CVE-2007-4639 can be exploited by remote authenticated users through specific SELECT statements.
What are the potential impacts of CVE-2007-4639?
The potential impacts of CVE-2007-4639 include a denial of service due to daemon crashes and possible execution of arbitrary code.