|
Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200505-12] PostgreSQL: Multiple vulnerabilities Vulnerability Scan
Vulnerability Scan Summary PostgreSQL: Multiple vulnerabilities
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200505-12
(PostgreSQL: Multiple vulnerabilities)
PostgreSQL gives public EXECUTE access to a number of character
conversion routines, but doesn't validate the given arguments
(CVE-2005-1409). It has also been reported that the contrib/tsearch2
module of PostgreSQL misdeclares the return value of some functions as
"internal" (CVE-2005-1410).
Impact
A possible hacker could call the character conversion routines with
specially setup arguments to crash the backend process of PostgreSQL or
to potentially gain administrator rights. A malicious user could also
call the misdeclared functions of the contrib/tsearch2 module,
resulting in a Denial of Service or other, yet uninvestigated, impacts.
Workaround
There is no known workaround at this time.
References:
http://www.postgresql.org/about/news.315
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1409
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-1410
http://www.postgresql.org/about/news.315
Solution:
All PostgreSQL users should update to the latest available version
and follow the guide at http://www.postgresql.o
rg/about/news.315
# emerge --sync
# emerge --ask --oneshot --verbose dev-db/postgresql
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.
|