Overview
PostgreSQL fails to properly recover from errors. This may allow an authenticated attacker to gain elevated privileges on a PostgreSQL database.
Description
PostgreSQL Database PostgreSQL is an open source database management system. |
Impact
An authenticated attacker may be able to gain elevated privileges on a PostgreSQL database. |
Solution
Upgrade This issue has been corrected in PostgreSQL version 8.1.3. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3
- http://archives.postgresql.org/pgsql-announce/2006-02/msg00008.php
- http://www.postgresql.org/docs/8.1/static/release-7-3-14.html
- http://www.postgresql.org/docs/8.1/static/release-7-4-12.html
- http://www.postgresql.org/docs/8.1/static/release-8-0-7.html
- http://secunia.com/advisories/18890/
Acknowledgements
This issue was reported in the release notes for PostgreSQL 8.1.3. PostgreSQL credits Akio Ishida with providing information regarding this issue.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-0553 |
Severity Metric: | 2.55 |
Date Public: | 2006-02-14 |
Date First Published: | 2006-02-27 |
Date Last Updated: | 2006-05-17 12:27 UTC |
Document Revision: | 18 |