Mandrake Linux Security Advisory : postgresql (MDKSA-2007:037-1)

high Nessus Plugin ID 24650

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

Jeff Trout discovered that the PostgreSQL server did not sufficiently check data types of SQL function arguments in some cases. A user could then exploit this to crash the database server or read out arbitrary locations of the server's memory, which could be used to retrieve database contents that the user should not be able to see. Note that a user must be authenticated in order to exploit this (CVE-2007-0555).

As well, Jeff Trout also discovered that the query planner did not verify that a table was still compatible with a previously-generated query plan, which could be exploited to read out arbitrary locations of the server's memory by using ALTER COLUMN TYPE during query execution. Again, a user must be authenticated in order to exploit this (CVE-2007-0556).

Update :

The previous update updated PostgreSQL to upstream versions, including 8.1.7 which contained a bug with typemod data types used with check constraints and expression indexes. This regression has been corrected in the new 8.1.8 version that is being provided.

Solution

Update the affected packages.

Plugin Details

Severity: High

ID: 24650

File Name: mandrake_MDKSA-2007-037.nasl

Version: 1.19

Type: local

Published: 2/18/2007

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:postgresql-plpython, p-cpe:/a:mandriva:linux:postgresql-pltcl, p-cpe:/a:mandriva:linux:postgresql-server, p-cpe:/a:mandriva:linux:postgresql-test, cpe:/o:mandriva:linux:2007, p-cpe:/a:mandriva:linux:lib64ecpg5, p-cpe:/a:mandriva:linux:lib64ecpg5-devel, p-cpe:/a:mandriva:linux:lib64pq4, p-cpe:/a:mandriva:linux:lib64pq4-devel, p-cpe:/a:mandriva:linux:libecpg5, p-cpe:/a:mandriva:linux:libecpg5-devel, p-cpe:/a:mandriva:linux:libpq4, p-cpe:/a:mandriva:linux:libpq4-devel, p-cpe:/a:mandriva:linux:postgresql, p-cpe:/a:mandriva:linux:postgresql-contrib, p-cpe:/a:mandriva:linux:postgresql-devel, p-cpe:/a:mandriva:linux:postgresql-docs, p-cpe:/a:mandriva:linux:postgresql-pl, p-cpe:/a:mandriva:linux:postgresql-plperl, p-cpe:/a:mandriva:linux:postgresql-plpgsql

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 2/8/2007

Reference Information

CVE: CVE-2007-0555, CVE-2007-0556

BID: 22387

MDKSA: 2007:037-1