Release date:
Updated on: 2012-03-13
Affected Systems:
Debian Linux 6.0 x
Perl-DBD-Pg 2.18.1-1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52378
Perl DBI is a database connection API in Perl. Perl-DBD-Pg allows Perl programs to connect to PostgreSQL database servers.
The Perl-DBD-Pg module of perl has multiple format string vulnerabilities in forwarding database notifications to corresponding warning messages and preparing specific DBD statements, attackers can exploit these vulnerabilities to reject access and execute arbitrary code.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 801733
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Debian
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.debian.org/security/