Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2010-0742

Опубликовано: 06 окт. 2010
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2010-0742: postgresql and postgresql84 security update (MODERATE)

postgresql:

[8.1.22-1.el5_5.1]

postgresql84:

[8.4.5-1.el5_5.1]

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

postgresql

8.1.22-1.el5_5.1

postgresql-contrib

8.1.22-1.el5_5.1

postgresql-devel

8.1.22-1.el5_5.1

postgresql-docs

8.1.22-1.el5_5.1

postgresql-libs

8.1.22-1.el5_5.1

postgresql-pl

8.1.22-1.el5_5.1

postgresql-python

8.1.22-1.el5_5.1

postgresql-server

8.1.22-1.el5_5.1

postgresql-tcl

8.1.22-1.el5_5.1

postgresql-test

8.1.22-1.el5_5.1

postgresql84

8.4.5-1.el5_5.1

postgresql84-contrib

8.4.5-1.el5_5.1

postgresql84-devel

8.4.5-1.el5_5.1

postgresql84-docs

8.4.5-1.el5_5.1

postgresql84-libs

8.4.5-1.el5_5.1

postgresql84-plperl

8.4.5-1.el5_5.1

postgresql84-plpython

8.4.5-1.el5_5.1

postgresql84-pltcl

8.4.5-1.el5_5.1

postgresql84-python

8.4.5-1.el5_5.1

postgresql84-server

8.4.5-1.el5_5.1

postgresql84-tcl

8.4.5-1.el5_5.1

postgresql84-test

8.4.5-1.el5_5.1

Oracle Linux x86_64

postgresql

8.1.22-1.el5_5.1

postgresql-contrib

8.1.22-1.el5_5.1

postgresql-devel

8.1.22-1.el5_5.1

postgresql-docs

8.1.22-1.el5_5.1

postgresql-libs

8.1.22-1.el5_5.1

postgresql-pl

8.1.22-1.el5_5.1

postgresql-python

8.1.22-1.el5_5.1

postgresql-server

8.1.22-1.el5_5.1

postgresql-tcl

8.1.22-1.el5_5.1

postgresql-test

8.1.22-1.el5_5.1

postgresql84

8.4.5-1.el5_5.1

postgresql84-contrib

8.4.5-1.el5_5.1

postgresql84-devel

8.4.5-1.el5_5.1

postgresql84-docs

8.4.5-1.el5_5.1

postgresql84-libs

8.4.5-1.el5_5.1

postgresql84-plperl

8.4.5-1.el5_5.1

postgresql84-plpython

8.4.5-1.el5_5.1

postgresql84-pltcl

8.4.5-1.el5_5.1

postgresql84-python

8.4.5-1.el5_5.1

postgresql84-server

8.4.5-1.el5_5.1

postgresql84-tcl

8.4.5-1.el5_5.1

postgresql84-test

8.4.5-1.el5_5.1

Oracle Linux i386

postgresql

8.1.22-1.el5_5.1

postgresql-contrib

8.1.22-1.el5_5.1

postgresql-devel

8.1.22-1.el5_5.1

postgresql-docs

8.1.22-1.el5_5.1

postgresql-libs

8.1.22-1.el5_5.1

postgresql-pl

8.1.22-1.el5_5.1

postgresql-python

8.1.22-1.el5_5.1

postgresql-server

8.1.22-1.el5_5.1

postgresql-tcl

8.1.22-1.el5_5.1

postgresql-test

8.1.22-1.el5_5.1

postgresql84

8.4.5-1.el5_5.1

postgresql84-contrib

8.4.5-1.el5_5.1

postgresql84-devel

8.4.5-1.el5_5.1

postgresql84-docs

8.4.5-1.el5_5.1

postgresql84-libs

8.4.5-1.el5_5.1

postgresql84-plperl

8.4.5-1.el5_5.1

postgresql84-plpython

8.4.5-1.el5_5.1

postgresql84-pltcl

8.4.5-1.el5_5.1

postgresql84-python

8.4.5-1.el5_5.1

postgresql84-server

8.4.5-1.el5_5.1

postgresql84-tcl

8.4.5-1.el5_5.1

postgresql84-test

8.4.5-1.el5_5.1

Связанные CVE

Связанные уязвимости

ubuntu
больше 14 лет назад

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.

redhat
больше 14 лет назад

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.

nvd
больше 14 лет назад

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.

debian
больше 14 лет назад

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30 ...

github
около 3 лет назад

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.