 |
|
|
|
| PostgreSQL multiple security vulnerabilities | | Published: |  | 22.09.2009 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 10252 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Denial of Service, privilege escalation, LDAP authentication bypass. |
| Affected: |  | POSTGRES : PostgreSQL 8.2 | | |  | POSTGRES : PostgreSQL 8.3 | | |  | POSTGRESQL : PostgreSQL 8.4 | | CVE: |  | CVE-2009-3231 (The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.) | | |  | CVE-2009-3230 (The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.) | | |  | CVE-2009-3229 (The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.) |
Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) updated since 21.09.2009 | | Published: |  | 22.09.2009 | | Source: |  | | | SecurityVulns ID: |  | 10249 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
|
|
|
|
|
|
|
|