First published: Fri Jan 11 2008(Updated: )
PostgreSQL is an advanced Object-Relational database management system<br>(DBMS). The postgresql packages include the client programs and libraries<br>needed to access a PostgreSQL DBMS server.<br>Will Drewry discovered multiple flaws in PostgreSQL's regular expression<br>engine. An authenticated attacker could use these flaws to cause a denial<br>of service by causing the PostgreSQL server to crash, enter an infinite<br>loop, or use extensive CPU and memory resources while processing queries<br>containing specially crafted regular expressions. Applications that accept<br>regular expressions from untrusted sources may expose this problem to<br>unauthorized attackers. (CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)<br>A privilege escalation flaw was discovered in PostgreSQL. An authenticated<br>attacker could create an index function that would be executed with<br>administrator privileges during database maintenance tasks, such as<br>database vacuuming. (CVE-2007-6600)<br>A privilege escalation flaw was discovered in PostgreSQL's Database Link<br>library (dblink). An authenticated attacker could use dblink to possibly<br>escalate privileges on systems with "trust" or "ident" authentication<br>configured. Please note that dblink functionality is not enabled by<br>default, and can only by enabled by a database administrator on systems<br>with the postgresql-contrib package installed. (CVE-2007-3278,<br>CVE-2007-6601)<br>All postgresql users should upgrade to these updated packages, which<br>include PostgreSQL 7.4.19 and 8.1.11, and resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/postgresql | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-contrib | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-devel | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-devel | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-docs | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-libs | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-libs | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-pl | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-python | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-server | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-tcl | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-test | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-contrib | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-docs | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-pl | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-python | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-server | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-tcl | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql-test | <8.1.11-1.el5_1.1 | 8.1.11-1.el5_1.1 |
redhat/postgresql | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-contrib | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-devel | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-docs | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-jdbc | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-libs | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-libs | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-pl | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-python | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-server | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-tcl | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-test | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-contrib | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-devel | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-docs | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-jdbc | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-pl | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-python | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-server | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-tcl | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
redhat/postgresql-test | <7.4.19-1.el4_6.1 | 7.4.19-1.el4_6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.