Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-0556

Опубликовано: 06 фев. 2007
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 6.6

Описание

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.

РелизСтатусПримечание
dapper

released

8.1.9-0ubuntu0.6.06
devel

released

8.1.8-1ubuntu3
edgy

released

8.1.9-0ubuntu0.6.10
feisty

released

8.1.8-1ubuntu3
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

8.2.5-1
edgy

DNE

feisty

released

8.2.4-0ubuntu0.7.04
upstream

needs-triage

Показывать по

EPSS

Процентиль: 82%
0.01918
Низкий

6.6 Medium

CVSS2

Связанные уязвимости

redhat
больше 18 лет назад

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.

nvd
больше 18 лет назад

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.

debian
больше 18 лет назад

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8 ...

github
около 3 лет назад

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.

oracle-oval
около 18 лет назад

ELSA-2007-0336: Moderate: postgresql security update (MODERATE)

EPSS

Процентиль: 82%
0.01918
Низкий

6.6 Medium

CVSS2