PT-2007-2015 · Postgresql+1 · Postgresql+1

Published

2007-02-06

·

Updated

2023-01-19

·

CVE-2007-0555

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 7.3 through 7.3.12 PostgreSQL versions 7.4 through 7.4.15 PostgreSQL versions 8.0 through 8.0.10 PostgreSQL versions 8.1 through 8.1.6 PostgreSQL versions 8.2 through 8.2.1
Description The issue allows attackers to disable certain checks for the data types of SQL function arguments. This can be exploited by remote authenticated users to cause a denial of service, resulting in a server crash, and potentially access database content that they should not be able to access.
Recommendations For PostgreSQL versions 7.3 through 7.3.12, update to version 7.3.13 or later. For PostgreSQL versions 7.4 through 7.4.15, update to version 7.4.16 or later. For PostgreSQL versions 8.0 through 8.0.10, update to version 8.0.11 or later. For PostgreSQL versions 8.1 through 8.1.6, update to version 8.1.7 or later. For PostgreSQL versions 8.2 through 8.2.1, update to version 8.2.2 or later.

Fix

Related Identifiers

CVE-2007-0555
DSA-1261-1
RHSA-2007:0064
RHSA-2007:0067
RHSA-2007:0068
RHSA-2007_0064
RHSA-2007_0068

Affected Products

Postgresql
Red Hat