PT-2007-5797 · Enterprisedb · Enterprisedb Advanced Server

Published

2007-08-31

·

Updated

2024-02-09

·

CVE-2007-4639

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: EnterpriseDB Advanced Server version 8.2
Description: The issue arises from improper handling of certain debugging function calls before a call to pldbg create listener, allowing remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg function. This can be demonstrated by invoking functions such as pldbg get stack and pldbg abort target, which can trigger the use of an uninitialized pointer.
Recommendations: For EnterpriseDB Advanced Server version 8.2, as a temporary workaround, consider disabling the debugging functions pldbg get stack and pldbg abort target until a patch is available. Restrict access to the pldbg functions to minimize the risk of exploitation. Avoid using the pldbg functions in SELECT statements until the issue is resolved.

Exploit

Fix

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

CVE-2007-4639
RHSA-2007:0895

Affected Products

Enterprisedb Advanced Server