RHEL 2.1 : postgresql (RHSA-2003:314)

high Nessus Plugin ID 12430

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

Updated PostgreSQL packages that correct a buffer overflow in the to_ascii routines are now available.

PostgreSQL is an advanced Object-Relational database management system (DBMS).

Two bugs that can lead to buffer overflows have been found in the PostgreSQL abstract data type to ASCII conversion routines. A remote attacker who is able to influence the data passed to the to_ascii functions may be able to execute arbitrary code in the context of the PostgreSQL server. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0901 to these issues.

In addition, a bug that can lead to leaks has been found in the string to timestamp abstract data type conversion routine. If the input string to the to_timestamp() routine is shorter than what the template string is expecting, the routine will run off the end of the input string, resulting in a leak and unstable behaviour.

Users of PostgreSQL are advised to upgrade to these erratum packages, which contain a backported patch that corrects these issues.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/cve/cve-2003-0901

http://www.nessus.org/u?2a5be090

https://access.redhat.com/errata/RHSA-2003:314

Plugin Details

Severity: High

ID: 12430

File Name: redhat-RHSA-2003-314.nasl

Version: 1.28

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:postgresql-tk, p-cpe:/a:redhat:enterprise_linux:postgresql-tcl, p-cpe:/a:redhat:enterprise_linux:postgresql-contrib, p-cpe:/a:redhat:enterprise_linux:postgresql-odbc, p-cpe:/a:redhat:enterprise_linux:postgresql-test, p-cpe:/a:redhat:enterprise_linux:postgresql-jdbc, p-cpe:/a:redhat:enterprise_linux:postgresql-python, p-cpe:/a:redhat:enterprise_linux:postgresql-docs, p-cpe:/a:redhat:enterprise_linux:postgresql-libs, p-cpe:/a:redhat:enterprise_linux:postgresql-perl, p-cpe:/a:redhat:enterprise_linux:postgresql, p-cpe:/a:redhat:enterprise_linux:postgresql-devel, p-cpe:/a:redhat:enterprise_linux:postgresql-server, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 11/12/2003

Vulnerability Publication Date: 11/3/2003

Reference Information

CVE: CVE-2003-0901

BID: 8741

RHSA: 2003:314