Revision Date: | 2013-04-29 | Version: | 12 | Title: | PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230. | Description: | PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230. | Family: | unix | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2009-4136
| Platform(s): | CentOS Linux 3 CentOS Linux 4 CentOS Linux 5 Oracle Linux 4 Oracle Linux 5 Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5
| Product(s): | | Definition Synopsis | OS Section: RHEL3, CentOS3 RHEL3 or CentOS3
The operating system installed on the system is Red Hat Enterprise Linux 3
OR CentOS Linux 3.x
AND Configuration section
rh-postgresql-devel is earlier than 0:7.3.21-3
OR rh-postgresql-server is earlier than 0:7.3.21-3
OR rh-postgresql-python is earlier than 0:7.3.21-3
OR rh-postgresql-libs is earlier than 0:7.3.21-3
OR rh-postgresql-docs is earlier than 0:7.3.21-3
OR rh-postgresql-test is earlier than 0:7.3.21-3
OR rh-postgresql-pl is earlier than 0:7.3.21-3
OR rh-postgresql-tcl is earlier than 0:7.3.21-3
OR rh-postgresql is earlier than 0:7.3.21-3
OR rh-postgresql-contrib is earlier than 0:7.3.21-3
OR rh-postgresql-jdbc is earlier than 0:7.3.21-3
OR OS Section: RHEL4, CentOS4, Oracle Linux 4
RHEL4, CentOS4 or Oracle Linux 4
The operating system installed on the system is Red Hat Enterprise Linux 4
OR CentOS Linux 4.x
OR Oracle Linux 4.x
AND Configuration section
postgresql is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-docs is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-pl is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-tcl is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-libs is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-contrib is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-python is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-test is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-jdbc is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-server is earlier than 0:7.4.29-1.el4_8.1
OR postgresql-devel is earlier than 0:7.4.29-1.el4_8.1
OR OS Section: RHEL5, CentOS5, Oracle Linux 5
RHEL5, CentOS5 or Oracle Linux 5
The operating system installed on the system is Red Hat Enterprise Linux 5
OR The operating system installed on the system is CentOS Linux 5.x
OR Oracle Linux 5.x
AND Configuration section
postgresql is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-docs is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-pl is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-tcl is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-libs is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-contrib is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-python is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-test is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-server is earlier than 0:8.1.21-1.el5_5.1
OR postgresql-devel is earlier than 0:8.1.21-1.el5_5.1
|
|