Release date:
Updated on:
Affected Systems:
PostgreSQL 9.1
PostgreSQL 9.0
PostgreSQL 8.4
PostgreSQL 8.3
Unaffected system:
PostgreSQL 9.0.7
PostgreSQL 8.4.11
PostgreSQL 8.3.18
PostgreSQL 9.1.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52188
Cve id: CVE-2012-0866, CVE-2012-0867, CVE-2012-0868
PostgreSQL is an advanced object-relational database management system that supports extended SQL standard subsets.
PostgreSQL has security vulnerabilities such as permission escalation, SSL certificate verification bypass, and SQL injection. Attackers can exploit these vulnerabilities to perform illegal operations, man-in-the-middle attacks, simulate trusted servers, and access or modify data.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PostgreSQL
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.postgresql.org