Packages
Details
Nico Leidecker discovered that PostgreSQL did not properly
restrict dblink functions. An authenticated user could exploit
this flaw to access arbitrary accounts and execute arbitrary
SQL queries. (CVE-2007-3278, CVE-2007-6601)
It was discovered that the TCL regular expression parser used
by PostgreSQL did not properly check its input. An attacker
could send crafted regular expressions to PostgreSQL and cause
a denial of service via resource exhaustion or database crash.
(CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)
It was discovered that PostgreSQL executed VACUUM and ANALYZE
operations within index functions with superuser privileges and
also allowed SET ROLE and SET SESSION AUTHORIZATION within index
functions. A remote authenticated...
Nico Leidecker discovered that PostgreSQL did not properly
restrict dblink functions. An authenticated user could exploit
this flaw to access arbitrary accounts and execute arbitrary
SQL queries. (CVE-2007-3278, CVE-2007-6601)
It was discovered that the TCL regular expression parser used
by PostgreSQL did not properly check its input. An attacker
could send crafted regular expressions to PostgreSQL and cause
a denial of service via resource exhaustion or database crash.
(CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)
It was discovered that PostgreSQL executed VACUUM and ANALYZE
operations within index functions with superuser privileges and
also allowed SET ROLE and SET SESSION AUTHORIZATION within index
functions. A remote authenticated user could exploit these flaws
to gain privileges. (CVE-2007-6600)
Update instructions
In general, a standard system upgrade is sufficient to effect the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
7.10 gutsy | postgresql-8.2 – 8.2.6-0ubuntu0.7.10.1 | ||
postgresql-pltcl-8.2 – 8.2.6-0ubuntu0.7.10.1 | |||
7.04 feisty | postgresql-8.2 – 8.2.6-0ubuntu0.7.04.1 | ||
postgresql-pltcl-8.2 – 8.2.6-0ubuntu0.7.04.1 | |||
6.10 edgy | postgresql-8.1 – 8.1.11-0ubuntu0.6.10.1 | ||
postgresql-pltcl-8.1 – 8.1.11-0ubuntu0.6.10.1 | |||
6.06 dapper | postgresql-8.1 – 8.1.11-0ubuntu0.6.06.1 | ||
postgresql-pltcl-8.1 – 8.1.11-0ubuntu0.6.06.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.