First published: Tue May 08 2007(Updated: )
PostgreSQL is an advanced Object-Relational database management system<br>(DBMS).<br>A flaw was found in the way PostgreSQL allows authenticated users to<br>execute security-definer functions. It was possible for an unprivileged<br>user to execute arbitrary code with the privileges of the security-definer<br>function. (CVE-2007-2138)<br>Users of PostgreSQL should upgrade to these updated packages containing<br>PostgreSQL version 8.1.9, 7.4.17, and 7.3.19 which corrects this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/postgresql | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-contrib | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-devel | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-devel | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-docs | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-libs | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-libs | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-pl | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-python | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-server | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-tcl | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-test | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-contrib | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-docs | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-pl | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-python | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-server | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-tcl | <8.1.9-1.el5 | 8.1.9-1.el5 |
redhat/postgresql-test | <8.1.9-1.el5 | 8.1.9-1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.