Solution
Please Install the Updated Packages.
Insight
Jeff Trout discovered that the PostgreSQL server did not sufficiently check data types of SQL function arguments in some cases. A user could then exploit this to crash the database server or read out arbitrary locations of the server's memory, which could be used to retrieve database contents that the user should not be able to see. Note that a user must be authenticated in order to exploit this (CVE-2007-0555).
As well, Jeff Trout also discovered that the query planner did not verify that a table was still compatible with a previously-generated query plan, which could be exploted to read out arbitrary locations of the server's memory by using ALTER COLUMN TYPE during query execution.
Again, a user must be authenticated in order to exploit this (CVE-2007-0556).
Updated packages have been patched to correct these issues.
Affected
postgresql on Mandriva Linux 2006.0,
Mandriva Linux 2006.0/X86_64,
Mandriva Linux 2007.0,
Mandriva Linux 2007.0/X86_64
Severity
Classification
-
CVE CVE-2007-0555, CVE-2007-0556 -
CVSS Base Score: 8.5
AV:N/AC:L/Au:S/C:C/I:N/A:C
Related Vulnerabilities