PT-2009-5545 · Postgresql · Postgresql
Tomas Hoger
·
Publicado
2009-09-17
·
Atualizado
2018-10-10
·
CVE-2009-3229
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 8.2 through 8.2.13
PostgreSQL versions 8.3 through 8.3.7
PostgreSQL versions 8.4 through 8.4.0
Description
The issue allows remote authenticated users to cause a denial of service by shutting down the backend server. This can be achieved by re-LOAD-ing libraries from a certain plugins directory, specifically
$libdir/plugins, if any libraries are present there.Recommendations
For PostgreSQL versions 8.2 through 8.2.13, update to version 8.2.14 or later.
For PostgreSQL versions 8.3 through 8.3.7, update to version 8.3.8 or later.
For PostgreSQL versions 8.4 through 8.4.0, update to version 8.4.1 or later.
As a temporary workaround, consider restricting access to the
$libdir/plugins directory to prevent re-LOAD-ing of libraries.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Postgresql