PT-2007-5797 · Enterprisedb · Enterprisedb Advanced Server
Published
2007-08-31
·
Updated
2024-02-09
·
CVE-2007-4639
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
EnterpriseDB Advanced Server version 8.2
Description:
The issue arises from improper handling of certain debugging function calls before a call to
pldbg create listener, allowing remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg function. This can be demonstrated by invoking functions such as pldbg get stack and pldbg abort target, which can trigger the use of an uninitialized pointer.Recommendations:
For EnterpriseDB Advanced Server version 8.2, as a temporary workaround, consider disabling the debugging functions
pldbg get stack and pldbg abort target until a patch is available. Restrict access to the pldbg functions to minimize the risk of exploitation. Avoid using the pldbg functions in SELECT statements until the issue is resolved.Exploit
Fix
Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enterprisedb Advanced Server