From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-200502-19.xml | 71 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 71 insertions(+) create mode 100644 glsa-200502-19.xml (limited to 'glsa-200502-19.xml') diff --git a/glsa-200502-19.xml b/glsa-200502-19.xml new file mode 100644 index 00000000..1eb8528b --- /dev/null +++ b/glsa-200502-19.xml @@ -0,0 +1,71 @@ + + + + + + + PostgreSQL: Buffer overflows in PL/PgSQL parser + + PostgreSQL is vulnerable to several buffer overflows in the PL/PgSQL parser + leading to execution of arbitrary code. + + postgresql + February 14, 2005 + June 26, 2007: 04 + 81350 + remote + + + 7.3* + 7.4* + 8.0.1-r1 + 7.3.9-r1 + 7.4.13 + 8.0.1-r1 + + + +

+ PostgreSQL is a SQL compliant, open source object-relational database + management system. +

+
+ +

+ PostgreSQL is vulnerable to several buffer overflows in the PL/PgSQL + parser. +

+
+ +

+ A remote attacker could send a malicious query resulting in the + execution of arbitrary code with the permissions of the user running + PostgreSQL. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All PostgreSQL users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose dev-db/postgresql +
+ + CAN-2005-0247 + + + koon + + + jaervosz + + + koon + +
-- cgit v1.2.3-65-gdbad