First published: Fri Jan 11 2008(Updated: )
PostgreSQL is an advanced Object-Relational database management system<br>(DBMS). The postgresql packages include the client programs and libraries<br>needed to access a PostgreSQL DBMS server.<br>A privilege escalation flaw was discovered in PostgreSQL. An authenticated<br>attacker could create an index function that would be executed with<br>administrator privileges during database maintenance tasks, such as<br>database vacuuming. (CVE-2007-6600)<br>A privilege escalation flaw was discovered in PostgreSQL's Database Link<br>library (dblink). An authenticated attacker could use dblink to possibly<br>escalate privileges on systems with "trust" or "ident" authentication<br>configured. Please note that dblink functionality is not enabled by<br>default, and can only by enabled by a database administrator on systems<br>with the postgresql-contrib package installed.<br>(CVE-2007-3278, CVE-2007-6601)<br>All postgresql users should upgrade to these updated packages, which<br>include PostgreSQL 7.3.21 and resolve these issues.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2008:0039 is classified as a moderate severity vulnerability due to the potential for privilege escalation by an authenticated attacker.
To mitigate RHSA-2008:0039, you should update PostgreSQL to the latest available version that resolves the privilege escalation flaw.
RHSA-2008:0039 affects users of PostgreSQL who have installed the vulnerable versions of the database software.
RHSA-2008:0039 is a privilege escalation vulnerability that allows authenticated attackers to gain higher access privileges.
RHSA-2008:0039 was disclosed in February 2008, prompting users to take action to secure their PostgreSQL installations.