[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-834-1 -- PostgreSQL vulnerabilities

ID: oval:org.secpod.oval:def:700403Date: (C)2011-05-13   (M)2024-02-19
Class: PATCHFamily: unix




It was discovered that PostgreSQL could be made to unload and reload an already loaded module by using the LOAD command. A remote authenticated attacker could exploit this to cause a denial of service. This issue did not affect Ubuntu 6.06 LTS. Due to an incomplete fix for CVE-2007-6600, RESET ROLE and RESET SESSION AUTHORIZATION operations were allowed inside security-definer functions. A remote authenticated attacker could exploit this to escalate privileges within PostgreSQL. It was discovered that PostgreSQL did not properly perform LDAP authentication under certain circumstances. When configured to use LDAP with anonymous binds, a remote attacker could bypass authentication by supplying an empty password. This issue did not affect Ubuntu 6.06 LTS

Platform:
Ubuntu 8.04
Ubuntu 9.04
Ubuntu 6.06
Ubuntu 8.10
Product:
PostgreSQL
Reference:
USN-834-1
CVE-2009-3229
CVE-2009-3230
CVE-2009-3231
CVE-2007-6600
CVE    4
CVE-2007-6600
CVE-2009-3231
CVE-2009-3230
CVE-2009-3229
...
CPE    4
cpe:/o:ubuntu:ubuntu_linux:8.04
cpe:/o:ubuntu:ubuntu_linux:8.10
cpe:/o:ubuntu:ubuntu_linux:9.04
cpe:/o:ubuntu:ubuntu_linux:6.06
...

© SecPod Technologies