PostgreSQL Multiple Security Vulnerabilities
BID:52188
Info
PostgreSQL Multiple Security Vulnerabilities
| Bugtraq ID: | 52188 |
| Class: | Unknown |
| CVE: |
CVE-2012-0866 CVE-2012-0867 CVE-2012-0868 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2012 12:00AM |
| Updated: | Apr 16 2015 06:13PM |
| Credit: | The vendor reported this issue |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server PostgreSQL PostgreSQL 9.1 PostgreSQL PostgreSQL 9.0 PostgreSQL PostgreSQL 8.4 PostgreSQL PostgreSQL 8.3 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
PostgreSQL PostgreSQL 9.1.3 PostgreSQL PostgreSQL 9.0.7 PostgreSQL PostgreSQL 8.4.11 PostgreSQL PostgreSQL 8.3.18 Avaya Aura Conferencing 6.0 SP1 Standard |
Discussion
PostgreSQL Multiple Security Vulnerabilities
PostgreSQL is prone to multiple security vulnerabilities, including:
1. A privilege-escalation vulnerability
2. An SSL certificate validation security-bypass vulnerability
3. An SQL-injection vulnerability
Attackers can exploit these issues to perform certain actions with elevated privileges, man-in-the-middle attacks, impersonate trusted servers, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
PostgreSQL is prone to multiple security vulnerabilities, including:
1. A privilege-escalation vulnerability
2. An SSL certificate validation security-bypass vulnerability
3. An SQL-injection vulnerability
Attackers can exploit these issues to perform certain actions with elevated privileges, man-in-the-middle attacks, impersonate trusted servers, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Exploit / POC
PostgreSQL Multiple Security Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PostgreSQL Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1 x86_64
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva lib64ecpg8.4_6-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64pq8.4_5-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-contrib-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-devel-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-docs-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-pl-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-plperl-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-plpgsql-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-plpython-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-pltcl-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.4-server-8.4.11-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva lib64ecpg8.3_6-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64pq8.3_5-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-contrib-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-devel-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-docs-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-pl-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-plperl-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-plpgsql-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-plpython-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-pltcl-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-server-8.3.18-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva libecpg8.3_6-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpq8.3_5-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-contrib-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-devel-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-docs-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-pl-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-plperl-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-plpgsql-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-plpython-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-pltcl-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva postgresql8.3-server-8.3.18-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
References
PostgreSQL Multiple Security Vulnerabilities
References:
References:
- Bug 797222 - (CVE-2012-0866) CVE-2012-0866 postgresql: Absent permission checks (Jan Lieskovsky )
- Bug 797915 - (CVE-2012-0867) CVE-2012-0867 postgresql: MITM due improper x509_v3 (Jan Lieskovsky)
- Bug 797917 - (CVE-2012-0868) CVE-2012-0868 postgresql: SQL injection due unsanit (Jan Lieskovsky)
- PostgreSQL Homepage (PostgreSQL)
- Security Information (PostgreSQL)