Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Debian: DSA-2051-1 Moderate: PostgreSQL Local Issues Report

debian
Calendar Grey May 24, 2010
Debian Logo
Debian DSA-3051-2 outlines various local vulnerabilities identified in MySQL and offers guidance on how to implement updates to enhance security.
Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database

Summary

Several local vulnerabilities have been discovered in PostgreSQL, an
object-relational SQL database. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2010-1169

Tim Bunce discovered that the implementation of the procedural
language PL/Perl insufficiently restricts the subset of allowed
code, which allows authenticated users the execution of arbitrary
Perl code.

CVE-2010-1170

Tom Lane discovered that the implementation of the procedural
language PL/Tcl insufficiently restricts the subset of allowed
code, which allows authenticated users the execution of arbitrary
Tcl code.

CVE-2010-1975

It was discovered that an unprivileged user could reset
superuser-only parameter settings.

For the stable distribution (lenny), these problems have been fixed in
version 8.3.11-0lenny1. This update also introduces a fix for
CVE-2010-0442, which was originally scheduled for the next Lenny point
update.

For the unstable distribution (sid), thes...

Read the Full Advisory

Package: postgresql-8.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here