Mandrake Linux Security Advisory : postgresql (MDKSA-2007:094)

Medium Nessus Plugin ID 25115


The remote Mandrake Linux host is missing one or more security updates.


A weakness in previous versions of PostgreSQL was found in the security definer functions in which an authenticated but otherwise unprivileged SQL user could use temporary objects to execute arbitrary code with the privileges of the security-definer function.


In addition, packages for Corporate Server/Desktop 3.0 have been updated to the latest PostgreSQL 7.4.17 which requires some attention when upgrading. To take advantage of the new version, and to ensure data coherency, we strongly recommend dumping the old databases, re-initializing the database, and then reloading the dumped data. This can be accomplished as root using :

# service postgresql start # su - postgres $ pg_dumpall >/tmp/database.dump $ exit # service postgresql stop # mv /var/lib/pgsql /var/lib/pgsql.bk # urpmi.update -a && urpmi
--auto-select # service postgresql start # service postgresql restart # su - postgres $ /usr/bin/psql -d template1 -f /tmp/database.dump $ exit

Only Corporate Server/Desktop 3.0 requires the dump/reload steps; the other Mandriva Linux platforms do not require this step. Notice that the double-restart of the postgresql service is in fact required.

Updated packages have been patched to correct this issue.


Update the affected packages.

Plugin Details

Severity: Medium

ID: 25115

File Name: mandrake_MDKSA-2007-094.nasl

Version: $Revision: 1.13 $

Type: local

Published: 2007/04/30

Modified: 2013/06/01

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:lib64ecpg5, p-cpe:/a:mandriva:linux:lib64ecpg5-devel, p-cpe:/a:mandriva:linux:lib64pq4, p-cpe:/a:mandriva:linux:lib64pq4-devel, p-cpe:/a:mandriva:linux:lib64pq5, p-cpe:/a:mandriva:linux:lib64pq5-devel, p-cpe:/a:mandriva:linux:libecpg5, p-cpe:/a:mandriva:linux:libecpg5-devel, p-cpe:/a:mandriva:linux:libpq4, p-cpe:/a:mandriva:linux:libpq4-devel, p-cpe:/a:mandriva:linux:libpq5, p-cpe:/a:mandriva:linux:libpq5-devel, p-cpe:/a:mandriva:linux:postgresql, p-cpe:/a:mandriva:linux:postgresql-contrib, p-cpe:/a:mandriva:linux:postgresql-devel, p-cpe:/a:mandriva:linux:postgresql-docs, p-cpe:/a:mandriva:linux:postgresql-pl, p-cpe:/a:mandriva:linux:postgresql-plperl, p-cpe:/a:mandriva:linux:postgresql-plpgsql, p-cpe:/a:mandriva:linux:postgresql-plpython, p-cpe:/a:mandriva:linux:postgresql-pltcl, p-cpe:/a:mandriva:linux:postgresql-server, p-cpe:/a:mandriva:linux:postgresql-test, cpe:/o:mandriva:linux:2007, cpe:/o:mandriva:linux:2007.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2007/04/25

Reference Information

CVE: CVE-2007-2138

MDKSA: 2007:094