| VuXML ID | Description |
| e050119b-3856-11df-b2b2-002170daae37 | postgresql -- bitsubstr overflow
BugTraq reports:
PostgreSQL is prone to a buffer-overflow
vulnerability because the application fails to
perform adequate boundary checks on user-supplied
data.
Attackers can exploit this issue to execute
arbitrary code with elevated privileges or
crash the affected application.
Discovery 2010-01-27 Entry 2010-03-25 postgresql-server
ge 7.4 lt 7.4.28
ge 8.0 lt 8.0.24
ge 8.1 lt 8.1.20
ge 8.2 lt 8.2.16
ge 8.3 lt 8.3.10
ge 8.4 lt 8.4.3
37973
CVE-2010-0442
|
| a8864f8f-aa9e-11e1-a284-0023ae8e59f0 | databases/postgresql*-server -- crypt vulnerabilities
The PostgreSQL Global Development Group reports:
Today the PHP, OpenBSD and FreeBSD communities announced updates to
patch a security hole involving their crypt() hashing algorithms. This
issue is described in CVE-2012-2143. This vulnerability also affects a
minority of PostgreSQL users, and will be fixed in an update release on
June 4, 2012.
Affected users are those who use the crypt(text, text) function
with DES encryption in the optional pg_crypto module. Passwords
affected are those that contain characters that cannot be
represented with 7-bit ASCII. If a password contains a character
that has the most significant bit set (0x80), and DES encryption
is used, that character and all characters after it will be ignored.
Discovery 2012-05-30 Entry 2012-05-30 Modified 2012-05-31 postgresql-server
gt 8.3.* lt 8.3.18_1
gt 8.4.* lt 8.4.11_1
gt 9.0.* lt 9.0.7_2
gt 9.1.* lt 9.1.3_1
gt 9.2.* lt 9.2.b1_1
CVE-2012-2143
http://www.postgresql.org/about/news/1397/
http://git.postgresql.org/gitweb/?p=postgresql.git;a=patch;h=932ded2ed51e8333852e370c7a6dad75d9f236f9
|
| a8864f8f-aa9e-11e1-a284-0023ae8e59f0 | databases/postgresql*-server -- crypt vulnerabilities
The PostgreSQL Global Development Group reports:
Today the PHP, OpenBSD and FreeBSD communities announced updates to
patch a security hole involving their crypt() hashing algorithms. This
issue is described in CVE-2012-2143. This vulnerability also affects a
minority of PostgreSQL users, and will be fixed in an update release on
June 4, 2012.
Affected users are those who use the crypt(text, text) function
with DES encryption in the optional pg_crypto module. Passwords
affected are those that contain characters that cannot be
represented with 7-bit ASCII. If a password contains a character
that has the most significant bit set (0x80), and DES encryption
is used, that character and all characters after it will be ignored.
Discovery 2012-05-30 Entry 2012-05-30 Modified 2012-05-31 postgresql-server
gt 8.3.* lt 8.3.18_1
gt 8.4.* lt 8.4.11_1
gt 9.0.* lt 9.0.7_2
gt 9.1.* lt 9.1.3_1
gt 9.2.* lt 9.2.b1_1
CVE-2012-2143
http://www.postgresql.org/about/news/1397/
http://git.postgresql.org/gitweb/?p=postgresql.git;a=patch;h=932ded2ed51e8333852e370c7a6dad75d9f236f9
|
| 07234e78-e899-11e1-b38d-0023ae8e59f0 | databases/postgresql*-server -- multiple vulnerabilities
The PostgreSQL Global Development Group reports:
The PostgreSQL Global Development Group today released
security updates for all active branches of the PostgreSQL
database system, including versions 9.1.5, 9.0.9, 8.4.13 and
8.3.20. This update patches security holes associated with
libxml2 and libxslt, similar to those affecting other open
source projects. All users are urged to update their
installations at the first available opportunity
Users who are relying on the built-in XML functionality to
validate external DTDs will need to implement a workaround, as
this security patch disables that functionality. Users who are
using xslt_process() to fetch documents or stylesheets from
external URLs will no longer be able to do so. The PostgreSQL
project regrets the need to disable both of these features in
order to maintain our security standards. These security issues
with XML are substantially similar to issues patched recently
by the Webkit (CVE-2011-1774), XMLsec (CVE-2011-1425) and PHP5
(CVE-2012-0057) projects.
Discovery 2012-08-17 Entry 2012-08-17 postgresql-server
gt 8.3.* lt 8.3.20
gt 8.4.* lt 8.4.13
gt 9.0.* lt 9.0.9
gt 9.1.* lt 9.1.5
CVE-2012-3488
CVE-2012-3489
http://www.postgresql.org/about/news/1407/
|
| e050119b-3856-11df-b2b2-002170daae37 | postgresql -- bitsubstr overflow
BugTraq reports:
PostgreSQL is prone to a buffer-overflow
vulnerability because the application fails to
perform adequate boundary checks on user-supplied
data.
Attackers can exploit this issue to execute
arbitrary code with elevated privileges or
crash the affected application.
Discovery 2010-01-27 Entry 2010-03-25 postgresql-server
ge 7.4 lt 7.4.28
ge 8.0 lt 8.0.24
ge 8.1 lt 8.1.20
ge 8.2 lt 8.2.16
ge 8.3 lt 8.3.10
ge 8.4 lt 8.4.3
37973
CVE-2010-0442
|