Oval Definition:oval:org.mitre.oval:def:24230
Revision Date:2014-07-07Version:27
Title:RHSA-2014:0249: postgresql security update (Important)
Description:PostgreSQL is an advanced object-relational database management system(DBMS).Multiple stack-based buffer overflow flaws were found in the date/timeimplementation of PostgreSQL. An authenticated database user could providea specially crafted date/time value that, when processed, could causePostgreSQL to crash or, potentially, execute arbitrary code with thepermissions of the user running PostgreSQL. (CVE-2014-0063)Multiple integer overflow flaws, leading to heap-based buffer overflows,were found in various type input functions in PostgreSQL. An authenticateddatabase user could possibly use these flaws to crash PostgreSQL or,potentially, execute arbitrary code with the permissions of the userrunning PostgreSQL. (CVE-2014-0064)Multiple potential buffer overflow flaws were found in PostgreSQL.An authenticated database user could possibly use these flaws to crashPostgreSQL or, potentially, execute arbitrary code with the permissions ofthe user running PostgreSQL. (CVE-2014-0065)It was found that granting an SQL role to a database user in a PostgreSQLdatabase without specifying the "ADMIN" option allowed the grantee toremove other users from their granted role. An authenticated database usercould use this flaw to remove a user from an SQL role which they weregranted access to. (CVE-2014-0060)A flaw was found in the validator functions provided by PostgreSQL'sprocedural languages (PLs). An authenticated database user could possiblyuse this flaw to escalate their privileges. (CVE-2014-0061)A race condition was found in the way the CREATE INDEX command performedmultiple independent lookups of a table that had to be indexed. Anauthenticated database user could possibly use this flaw to escalate theirprivileges. (CVE-2014-0062)It was found that the chkpass extension of PostgreSQL did not check thereturn value of the crypt() function. An authenticated database user couldpossibly use this flaw to crash PostgreSQL via a null pointer dereference.(CVE-2014-0066)Red Hat would like to thank the PostgreSQL project for reporting theseissues. Upstream acknowledges Noah Misch as the original reporter ofCVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as theoriginal reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich asthe original reporters of CVE-2014-0065, Andres Freund as the originalreporter of CVE-2014-0061, Robert Haas and Andres Freund as the originalreporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as theoriginal reporters of CVE-2014-0066.These updated packages upgrade PostgreSQL to version 8.4.20, which fixesthese issues as well as several non-security issues. Refer to thePostgreSQL Release Notes for a full list of changes:http://www.postgresql.org/docs/8.4/static/release-8-4-19.htmlhttp://www.postgresql.org/docs/8.4/static/release-8-4-20.htmlAll PostgreSQL users are advised to upgrade to these updated packages,which contain backported patches to correct these issues. If the postgresqlservice is running, it will be automatically restarted after installingthis update.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:0249
CVE-2014-0060
CVE-2014-0061
CVE-2014-0062
CVE-2014-0063
CVE-2014-0064
CVE-2014-0065
CVE-2014-0066
RHSA-2014:0249-00
Platform(s):CentOS Linux 5
Red Hat Enterprise Linux 5
Product(s):postgresql
Definition Synopsis
  • Redhat 5 or Centos 5 release
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages section
  • postgresql-contrib is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-docs is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-devel is earlier than 0:8.1.23-10.el5_10
  • OR postgresql is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-test is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-pl is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-python is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-tcl is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-server is earlier than 0:8.1.23-10.el5_10
  • OR postgresql-libs is earlier than 0:8.1.23-10.el5_10
  • BACK