PT-2006-6256 · Postgresql+1 · Postgresql+1

Michael Fuhr

·

Published

2006-10-26

·

Updated

2023-10-12

·

CVE-2006-5541

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 7.4.1 through 7.4.14 PostgreSQL versions 8.0.x before 8.0.9 PostgreSQL versions 8.1.x before 8.1.5
Description The issue allows remote authenticated users to cause a denial of service, resulting in a daemon crash. This is due to a bug in the coercion of unknown literals to ANYARRAY. A valid login is required to exploit this issue.
Recommendations For versions 7.4.1 through 7.4.14, update to a version outside of this range to resolve the issue. For versions 8.0.x before 8.0.9, update to version 8.0.9 or later to resolve the issue. For versions 8.1.x before 8.1.5, update to version 8.1.5 or later to resolve the issue.

Fix

Related Identifiers

CVE-2006-5541
RHSA-2007:0067
RHSA-2007:0068
RHSA-2007_0068

Affected Products

Postgresql
Red Hat