Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-2658-1 Critical: PostgreSQL Remote Security Risks

debian
Calendar Grey April 4, 2013
Debian Logo
Enhance your PostgreSQL 9.1 installations to address various security vulnerabilities and safeguard your information.
Several vulnerabilities were discovered in PostgreSQL database server

Summary

Several vulnerabilities were discovered in PostgreSQL database server.

CVE-2013-1899

Mitsumasa Kondo and Kyotaro Horiguchi of NTT Open Source Software Center
discovered that it was possible for a connection request containing a
database name that begins with "-" to be crafted that can damage or destroy
files within a server's data directory. Anyone with access to the port the
PostgreSQL server listens on can initiate this request.

CVE-2013-1900

Random numbers generated by contrib/pgcrypto functions may be easy for
another database user to guess.

CVE-2013-1901

An unprivileged user could run commands that could interfere with
in-progress backups

For the stable distribution (squeeze), postgresql-9.1 is not available.
DSA-2657-1 has been released for CVE-2013-1900 affecting posgresql-8.4.

For the testing distribution (wheezy), these problems have been fixed in
version 9.1.9-0wheezy1.

For the unstable distribution (sid), these problems have been fixed in
version 9.1.9-1.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: postgresql-9.1
CVE ID: CVE-2013-1899 CVE-2013-1900 CVE-2013-1901

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here