PostgreSQL Postmaster Denial Of Service Vulnerability
BID:16201
Info
PostgreSQL Postmaster Denial Of Service Vulnerability
| Bugtraq ID: | 16201 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-0105 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2006 12:00AM |
| Updated: | Jan 11 2006 04:50PM |
| Credit: | This issue was disclosed by the vendor. The vendor credits Yoshiyuki Asaba with the discovery of this vulnerability. |
| Vulnerable: |
PostgreSQL PostgreSQL 8.0.2 PostgreSQL PostgreSQL 8.0.1 PostgreSQL PostgreSQL 8.0 PostgreSQL PostgreSQL 7.4.9 PostgreSQL PostgreSQL 7.4.8 PostgreSQL PostgreSQL 7.4.7 PostgreSQL PostgreSQL 7.4.6 PostgreSQL PostgreSQL 7.4.5 PostgreSQL PostgreSQL 7.4.3 PostgreSQL PostgreSQL 7.4 PostgreSQL PostgreSQL 7.3.9 PostgreSQL PostgreSQL 7.3.8 PostgreSQL PostgreSQL 7.3.6 PostgreSQL PostgreSQL 7.3.4 PostgreSQL PostgreSQL 7.3.3 PostgreSQL PostgreSQL 7.3.2 PostgreSQL PostgreSQL 7.3.1 PostgreSQL PostgreSQL 7.3 PDGSoft Shopping Cart 8.1 |
| Not Vulnerable: |
PDGSoft Shopping Cart 8.1.2 PDGSoft Shopping Cart 8.0.6 |
Discussion
PostgreSQL Postmaster Denial Of Service Vulnerability
PostgreSQL is prone to a denial of service vulnerability. This issue is due to a failure in the application to properly handle exceptional conditions.
A remote attacker can exploit this issue to crash the postmaster service, thus denying future connections until the service is manually restarted.
This issue only affects PostgreSQL for Microsoft Windows.
PostgreSQL is prone to a denial of service vulnerability. This issue is due to a failure in the application to properly handle exceptional conditions.
A remote attacker can exploit this issue to crash the postmaster service, thus denying future connections until the service is manually restarted.
This issue only affects PostgreSQL for Microsoft Windows.
Exploit / POC
PostgreSQL Postmaster Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PostgreSQL Postmaster Denial Of Service Vulnerability
Solution:
The vendor has released updated versions addressing this issue:
PostgreSQL PostgreSQL 8.0
PostgreSQL PostgreSQL 8.0.1
PostgreSQL PostgreSQL 8.0.2
PDGSoft Shopping Cart 8.1
Solution:
The vendor has released updated versions addressing this issue:
PostgreSQL PostgreSQL 8.0
-
PostgreSQL postgresql-8.0.6.tar.gz
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source/v8.0. 6/postgresql-8.0.6.tar.gz
PostgreSQL PostgreSQL 8.0.1
-
PostgreSQL postgresql-8.0.6.tar.gz
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source/v8.0. 6/postgresql-8.0.6.tar.gz
PostgreSQL PostgreSQL 8.0.2
-
PostgreSQL postgresql-8.0.6.tar.gz
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source/v8.0. 6/postgresql-8.0.6.tar.gz
PDGSoft Shopping Cart 8.1
-
PostgreSQL postgresql-8.1.2.tar.gz
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source/v8.1. 2/postgresql-8.1.2.tar.gz
References
PostgreSQL Postmaster Denial Of Service Vulnerability
References:
References:
- Minor Versions 8.1.2, 8.0.6 Released (PostgreSQL)
- PostgreSQL Project Homepage (PostgreSQL)
- PostgreSQL security releases 8.0.6 and 8.1.2 (PostgreSQL Security
)