Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

PostgreSQL < 8.0.3 Incorrect Function Declaration

Medium

Synopsis

The remote host is vulnerable to a flaw that allows for the bypassing of authentication.

Description

The remote host is running PostgreSQL, an open source relational database. This version is vulnerable to a number of flaws. Specifically, the following functions are directly accessible to remote users: dex_init() snb_en_init() snb_ru_init() spell_init() syn_init()

An attacker calling these functions can submit queries that lead to compromise of confidential data or execution of arbitrary code on the remote database server.

Solution

Upgrade to PostgreSQL 8.0.3 or higher.