PT-2007-2015 · Postgresql+1 · Postgresql+1
Published
2007-02-06
·
Updated
2023-01-19
·
CVE-2007-0555
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 7.3 through 7.3.12
PostgreSQL versions 7.4 through 7.4.15
PostgreSQL versions 8.0 through 8.0.10
PostgreSQL versions 8.1 through 8.1.6
PostgreSQL versions 8.2 through 8.2.1
Description
The issue allows attackers to disable certain checks for the data types of SQL function arguments. This can be exploited by remote authenticated users to cause a denial of service, resulting in a server crash, and potentially access database content that they should not be able to access.
Recommendations
For PostgreSQL versions 7.3 through 7.3.12, update to version 7.3.13 or later.
For PostgreSQL versions 7.4 through 7.4.15, update to version 7.4.16 or later.
For PostgreSQL versions 8.0 through 8.0.10, update to version 8.0.11 or later.
For PostgreSQL versions 8.1 through 8.1.6, update to version 8.1.7 or later.
For PostgreSQL versions 8.2 through 8.2.1, update to version 8.2.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Postgresql
Red Hat