Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-1463-1 Important Local Vulnerabilities in PostgreSQL

debian
Calendar Grey January 14, 2008
Debian Logo
Enhance postgresql-7.4 components to address various local security flaws in Debian. Important security notice enclosed.
Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database

Summary


It was discovered that the DBLink module performed insufficient
credential validation. This issue is also tracked as CVE-2007-6601,
since the initial upstream fix was incomplete.

CVE-2007-4769

Tavis Ormandy and Will Drewry discovered that a bug in the handling
of back-references inside the regular expressions engine could lead
to an out of bands read, resulting in a crash. This constitutes only
a security problem if an application using ProgreSQL processes
regular expressions from untrusted sources.

CVE-2007-4772

Tavis Ormandy and Will Drewry discovered that the optimizer for regular
expression could be tricked into an infinite loop, resulting in denial
of service. This constitutes only a security problem if an application
using ProgreSQL processes regular expressions from untrusted sources.

CVE-2007-6067

Tavis Ormandy and Will Drewry discovered that the optimizer for regular
expression could be tricked massive ressource...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here