[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1964 postgresql-7.4, postgresql-8.1, postgresql-8.3 -- several vulnerabilities

ID: oval:org.mitre.oval:def:6869Date: (C)2010-05-24   (M)2022-10-10
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in PostgreSQL, a database server. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that PostgreSQL did not properly verify the Common Name attribute in X.509 certificates, enabling attackers to bypass the TLS protection on client-server connections, by relying on a certificate from a trusted CA which contains an embedded NUL byte in the Common Name . Authenticated database users could elevate their privileges by creating specially-crafted index functions . The following matrix shows fixed source package versions for the respective distributions. In addition to these security fixes, the updates contain reliability improvements and fix other defects. We recommend that you upgrade your PostgreSQL packages.

Platform:
Debian 5.0
Debian 4.0
Product:
postgresql-7.4
postgresql-8.1
postgresql-8.3
Reference:
DSA-1964
CVE-2009-4034
CVE-2009-4136
CVE    2
CVE-2009-4034
CVE-2009-4136
CPE    2
cpe:/o:debian:debian_linux:4.x
cpe:/o:debian:debian_linux:5.x

© SecPod Technologies