Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> SuSE Local Security Checks >> SUSE-SA:2005:027: postgresql


Vulnerability Assessment Details

SUSE-SA:2005:027: postgresql

Vulnerability Assessment Summary
Check for the version of the postgresql package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory SUSE-SA:2005:027 (postgresql).


Several problems were identified and fixed in the PostgreSQL
database server.

Multiple buffer overflows in the low level parsing routines may
permit attackers to execute arbitrary code via:

(1) a large number of variables in a SQL statement being handled by
the read_sql_construct() function,

(2) a large number of INTO variables in a SELECT statement being
handled by the make_select_stmt function,

(3) a large number of arbitrary variables in a SELECT statement being
handled by the make_select_stmt function, and

(4) a large number of INTO variables in a FETCH statement being
handled by the make_fetch_stmt function.


This is tracked by the Mitre CVE ID CVE-2005-0247.


Solution : http://www.suse.de/security/advisories/2005_27_postgresql.html
Network Security Threat Level: Medium

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors


Dell PowerEdge VRTX Blade Server Enclosure Chassis Only NO HDD NO OS NO Blades picture

Dell PowerEdge VRTX Blade Server Enclosure Chassis Only NO HDD NO OS NO Blades

$399.99



Dell PowerEdge M620 Blade Server – HHB003 Xeon E5-2660 V2 2.2GHz 12V 37A picture

Dell PowerEdge M620 Blade Server – HHB003 Xeon E5-2660 V2 2.2GHz 12V 37A

$67.99



HP ProLiant BL460c Gen9 Blade 2x E5-2667v3 3.2GHz =16 Cores 256GB P244BR 650FLB picture

HP ProLiant BL460c Gen9 Blade 2x E5-2667v3 3.2GHz =16 Cores 256GB P244BR 650FLB

$303.00



HPE ProLiant BL460c Gen8 735151-B21 E5-v2 Blade Server LOADED w 512 GIGS MEMORY picture

HPE ProLiant BL460c Gen8 735151-B21 E5-v2 Blade Server LOADED w 512 GIGS MEMORY

$280.00



2 LOT Dell PowerEdge M620 Blade Server 0F9HJC Intel E5-2609 2.40GHz 16GB RAM  picture

2 LOT Dell PowerEdge M620 Blade Server 0F9HJC Intel E5-2609 2.40GHz 16GB RAM

$74.99



Dell PowerEdge M630 Blade Server 1x Xeon E5-2630 v4 CPU / Motherboard P/N 0R10KG picture

Dell PowerEdge M630 Blade Server 1x Xeon E5-2630 v4 CPU / Motherboard P/N 0R10KG

$42.47



Cisco B200 M3 Blade Server UCSB-B200-M3 2x Xeon E5-2680 16 Core 2.7GHz 256GB RAM picture

Cisco B200 M3 Blade Server UCSB-B200-M3 2x Xeon E5-2680 16 Core 2.7GHz 256GB RAM

$89.95



Dell PowerEdge FC830 blade server with 4x processors E5-4669v3 no memory  picture

Dell PowerEdge FC830 blade server with 4x processors E5-4669v3 no memory

$179.00



DELL PowerEdge M630 Blade 2x E5-2683v3 2.0GHz =28 Cores 256GB H330 2x10Gb X520 picture

DELL PowerEdge M630 Blade 2x E5-2683v3 2.0GHz =28 Cores 256GB H330 2x10Gb X520

$323.00



DELL PowerEdge M630 Blade 2x E5-2680v3 2.5GHz =24 Cores 256GB H330 2x10Gb X520 picture

DELL PowerEdge M630 Blade 2x E5-2680v3 2.5GHz =24 Cores 256GB H330 2x10Gb X520

$303.00



Discussions

No Discussions have been posted on this vulnerability.