Contact | Site en Français               

 


 

VUPEN VNS v4.0

 
  Features and Options
  Free 14-Day Trial

  Partner Program

  Receive More Information
 
   
 

Latest Intelligence

 
  VUPEN Security Advisories

  Virus and Malware Alerts

  VUPEN Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes PostgreSQL Two Security Bypass Vulnerabilities

Title : Fedora Security Update Fixes PostgreSQL Two Security Bypass Vulnerabilities
VUPEN ID : VUPEN/ADV-2006-1958
CVE ID : CVE-2006-2313 - CVE-2006-2314
CWE ID : VUPEN VNS Only
CVSS V2 : VUPEN VNS Only
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-05-24


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Fedora has released updated packages to address two vulnerabilities identified in PostgreSQL. These flaws could be exploited by attackers to bypass security restrictions. For additional information, see : VUPEN/ADV-2006-1941

Affected Products

Fedora Core 5
Fedora Core 4

Solution

Upgrade the affected packages :

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

a34d7c0a6b706d5a763d6fc995e0a9b0a815cacb SRPMS/postgresql-8.1.4-1.FC5.1.src.rpm
dd60e160a40544b67a2c7fe27c158719fdfc1917 ppc/postgresql-8.1.4-1.FC5.1.ppc.rpm
e9f4d668e152f42ed5a3f28bb3188c4e729883d0 ppc/postgresql-libs-8.1.4-1.FC5.1.ppc.rpm
7e925ecec192b2b76da0bffd2a7ebae5df4485a8 ppc/postgresql-server-8.1.4-1.FC5.1.ppc.rpm
e38b79b49d32c43f8a83def76fd932e6467bbb49 ppc/postgresql-docs-8.1.4-1.FC5.1.ppc.rpm
7f44b45f2a99cd94d6657cc61219907325c63096 ppc/postgresql-contrib-8.1.4-1.FC5.1.ppc.rpm
291ed9aa22ff53876304b9881b409f9866d3df72 ppc/postgresql-devel-8.1.4-1.FC5.1.ppc.rpm
7257574cad34756ae371d149820e3ed23ed7086a ppc/postgresql-pl-8.1.4-1.FC5.1.ppc.rpm
0af30bd295ba785c625f3293f7f86e93a82bd25b ppc/postgresql-tcl-8.1.4-1.FC5.1.ppc.rpm
3bf7f9673d1cc18889732dab401ce5bcd50aa5f3 ppc/postgresql-python-8.1.4-1.FC5.1.ppc.rpm
e1068aae04bb77fe72b44fa1a12f1aefdd850ed0 ppc/postgresql-jdbc-8.1.4-1.FC5.1.ppc.rpm
d807c2b6ae9aa55cf89cf3206b8e9e0dbe85f5b7 ppc/postgresql-test-8.1.4-1.FC5.1.ppc.rpm
394e603ff869ad004d57baf31f8b82cc4f21a885 ppc/debug/postgresql-debuginfo-8.1.4-1.FC5.1.ppc.rpm
7a32a01ab26a8bf5bd075e1354dfaf222d089ed3 ppc/postgresql-libs-8.1.4-1.FC5.1.ppc64.rpm
4f5ad0869cb13392f72440042deb4f6b1fb39aaa x86_64/postgresql-8.1.4-1.FC5.1.x86_64.rpm
1b94e84e0d05f79271607de6b56db70e9d68a79f x86_64/postgresql-libs-8.1.4-1.FC5.1.x86_64.rpm
7bced98a2825c7d742470ff221e774006d30f819 x86_64/postgresql-server-8.1.4-1.FC5.1.x86_64.rpm
2f0dbd361409dc67792b30d7e72fd9bddf780659 x86_64/postgresql-docs-8.1.4-1.FC5.1.x86_64.rpm
77d360f0b8b0a5875c04bef8b5a9d49171c71fc7 x86_64/postgresql-contrib-8.1.4-1.FC5.1.x86_64.rpm
a5480ac114612e4f0e0a06045e7492fd752621b3 x86_64/postgresql-devel-8.1.4-1.FC5.1.x86_64.rpm
d966973a2be9bdeccd2426dde176c14b76fc1c9d x86_64/postgresql-pl-8.1.4-1.FC5.1.x86_64.rpm
dc7a13c3c9d336af3c2a27435f0d2ba135bb6149 x86_64/postgresql-tcl-8.1.4-1.FC5.1.x86_64.rpm
4ad6a9afeb8d444b58311c92f62f561aca93bc54 x86_64/postgresql-python-8.1.4-1.FC5.1.x86_64.rpm
2ab4dbb07ba473b85064935e53d9b2a569574010 x86_64/postgresql-jdbc-8.1.4-1.FC5.1.x86_64.rpm
8fe3251551fc993f26a245ffc0b615dbe31a4a41 x86_64/postgresql-test-8.1.4-1.FC5.1.x86_64.rpm
68b2a90b5f2c29a3819587e89fac23f7889d216a x86_64/debug/postgresql-debuginfo-8.1.4-1.FC5.1.x86_64.rpm
03f18f7cd900bd1e424b8148822b1ee5bd6733c8 i386/postgresql-8.1.4-1.FC5.1.i386.rpm
42b06199f88fc25d263b9213e4ef36015001d9c4 i386/postgresql-libs-8.1.4-1.FC5.1.i386.rpm
5c85c0c58224a368f2041069d10bc7eb3c95e6df i386/postgresql-server-8.1.4-1.FC5.1.i386.rpm
e072f65cc9741b4b4da0bd236ff0ba944f526efb i386/postgresql-docs-8.1.4-1.FC5.1.i386.rpm
eb2acf6a13c4c63ce41de5540d39d797cdbe4709 i386/postgresql-contrib-8.1.4-1.FC5.1.i386.rpm
5a3a54df4886cd4f77872ad84795a6ce30e21752 i386/postgresql-devel-8.1.4-1.FC5.1.i386.rpm
baf6ed272be815681f62793416fd5e69cab47136 i386/postgresql-pl-8.1.4-1.FC5.1.i386.rpm
cc5527793c6e6a843970ee5e127b90f95cd38637 i386/postgresql-tcl-8.1.4-1.FC5.1.i386.rpm
2b7610b1e07279be2efada06f0bb0df27ccbd265 i386/postgresql-python-8.1.4-1.FC5.1.i386.rpm
2a2a14b3ea932124bfc2e407fece61da54254e0b i386/postgresql-jdbc-8.1.4-1.FC5.1.i386.rpm
527b83b87c2eee60f906a4b98ebda7bdec4556df i386/postgresql-test-8.1.4-1.FC5.1.i386.rpm
b45cd9031b0dc5748ce003813c4fd57f76a84a10 i386/debug/postgresql-debuginfo-8.1.4-1.FC5.1.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

72b710ffbcadcbd2af2911c6b0783700d9ddc965 SRPMS/postgresql-8.0.8-1.FC4.1.src.rpm
2e3c83c0b40ab8713f844b6738dea7e159856a71 ppc/postgresql-8.0.8-1.FC4.1.ppc.rpm
97c2e2b3950d32a0676b41dc03976bb255ef02ef ppc/postgresql-libs-8.0.8-1.FC4.1.ppc.rpm
4a569e72ee703b95d8aea8b1d90ee674a870ec4c ppc/postgresql-server-8.0.8-1.FC4.1.ppc.rpm
78944f4d959f4e0e8da6a60d72739e5b5bf28eed ppc/postgresql-docs-8.0.8-1.FC4.1.ppc.rpm
3ee5f3d6e119ba6995fdb81dbe14b96cc02dfb62 ppc/postgresql-contrib-8.0.8-1.FC4.1.ppc.rpm
82dc5025ce465524725795cedd6d6eb7bf223a59 ppc/postgresql-devel-8.0.8-1.FC4.1.ppc.rpm
c9c54b90f4192ddab578a0bfa60318b0707a9c88 ppc/postgresql-pl-8.0.8-1.FC4.1.ppc.rpm
b8643c6a1b756d0ceaa7f51cd552bf8aa2337d49 ppc/postgresql-tcl-8.0.8-1.FC4.1.ppc.rpm
f0b7e60f5d4a3a73e7084c98772a64dc3acdb3c3 ppc/postgresql-python-8.0.8-1.FC4.1.ppc.rpm
0e1c769b497e74f38240341c4c5f7f81c6d1bd06 ppc/postgresql-jdbc-8.0.8-1.FC4.1.ppc.rpm
8306c4d4d7db42840ba8eb0f57e3972f1b03c252 ppc/postgresql-test-8.0.8-1.FC4.1.ppc.rpm
a48fdcd8291c129d2b7c5d0ff2e396411227dfbb ppc/debug/postgresql-debuginfo-8.0.8-1.FC4.1.ppc.rpm
9d9507fabe3b59b6b45c2e28a11dc6d75cbaa65b ppc/postgresql-libs-8.0.8-1.FC4.1.ppc64.rpm
8c09c5203ae470bebac62050c1427668314de3e8 x86_64/postgresql-8.0.8-1.FC4.1.x86_64.rpm
2d1e60172e18504f013a71483d37477306c78c7f x86_64/postgresql-libs-8.0.8-1.FC4.1.x86_64.rpm
2bfb373ce9f9e1a22164b35e35b1e246e525b82b x86_64/postgresql-server-8.0.8-1.FC4.1.x86_64.rpm
195d6dcce353df23f14428d14401b763fe158e48 x86_64/postgresql-docs-8.0.8-1.FC4.1.x86_64.rpm
a4e53de0e33168eccf3defde7492f379af265fc4 x86_64/postgresql-contrib-8.0.8-1.FC4.1.x86_64.rpm
a8bc0effc0edc5acf60cdb9413ef30b1ee0794e7 x86_64/postgresql-devel-8.0.8-1.FC4.1.x86_64.rpm
a8fd08f97113c0e8e05a27cb3247fa7a4aa6f5c9 x86_64/postgresql-pl-8.0.8-1.FC4.1.x86_64.rpm
e572d5524f88989d697a9156dac3633293622db7 x86_64/postgresql-tcl-8.0.8-1.FC4.1.x86_64.rpm
3779fe8ac1c86f4e073facd47fd785fc6432ec79 x86_64/postgresql-python-8.0.8-1.FC4.1.x86_64.rpm
2e2f7bd9660c3f4906adcb0477b2a5225b838625 x86_64/postgresql-jdbc-8.0.8-1.FC4.1.x86_64.rpm
954f639669baf57bb95eeb0202cf81c0caeac63f x86_64/postgresql-test-8.0.8-1.FC4.1.x86_64.rpm
1eb9407b25091dd212d346e5990ccb7a93eb0f0d x86_64/debug/postgresql-debuginfo-8.0.8-1.FC4.1.x86_64.rpm
b1f3e226569f59ace6024df40b994b570badb831 i386/postgresql-8.0.8-1.FC4.1.i386.rpm
8d7e9a0675c04b24e4df1448ad1f257bc316bc79 i386/postgresql-libs-8.0.8-1.FC4.1.i386.rpm
edcb1ecadb943b924840e3bae894836da6c7803c i386/postgresql-server-8.0.8-1.FC4.1.i386.rpm
c285455ddc2c7a09367e2115472fe5f8858c0ac1 i386/postgresql-docs-8.0.8-1.FC4.1.i386.rpm
bdff12918232604d48ea3c9db505047e5cf269c5 i386/postgresql-contrib-8.0.8-1.FC4.1.i386.rpm
9584465b454a99fae65cc3eb36b248aa47dfe2e2 i386/postgresql-devel-8.0.8-1.FC4.1.i386.rpm
c8be30f64cdf448aea5ce3fa9f2bd67afd88d34b i386/postgresql-pl-8.0.8-1.FC4.1.i386.rpm
71ebdbf8514cbeadc8835320b2929683fca77bad i386/postgresql-tcl-8.0.8-1.FC4.1.i386.rpm
ae2c380b3e7bccf03fa6327e3970c374de502a4f i386/postgresql-python-8.0.8-1.FC4.1.i386.rpm
51de38d4fe8621d996ca4e7d5c324ad8c367ed0b i386/postgresql-jdbc-8.0.8-1.FC4.1.i386.rpm
25e24416855293ad59a9420a6a4f33a87edaab1b i386/postgresql-test-8.0.8-1.FC4.1.i386.rpm
9fc9ba0281301f61497daa8f3d7847937f926169 i386/debug/postgresql-debuginfo-8.0.8-1.FC4.1.i386.rpm

References

http://www.vupen.com/english/advisories/2006/1958
https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00115.html
https://www.redhat.com/archives/fedora-package-announce/2006-May/msg00116.html

ChangeLog

2006-05-24 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

VUPEN Vulnerability
Notification Service

 

Latest Advisories

  

   
    





Copyright VUPEN © 2004-2010 - Privacy Policy