PostgreSQL 'security definer' and 'set' attributes Remote Denial of Service Vulnerability
Release date:
Updated on: 2012-06-06
Affected Systems:
PostgreSQL 9.x
PostgreSQL 8.x
Unaffected system:
PostgreSQL 9.1.4
PostgreSQL 9.0.8
PostgreSQL 8.4.12
PostgreSQL 8.3.19
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53812
Cve id: CVE-2012-2655
PostgreSQL is an advanced object-relational database management system that supports extended SQL standard subsets.
PostgreSQL has a remote denial of service vulnerability in the implementation of alter function rename, which allows attackers to crash applications.
<* Source: Tom Lane
Link: http://archives.postgresql.org/pgsql-hackers/2012-05/msg01426.php
Http://archives.postgresql.org/pgsql-hackers/2012-05/msg01426.php
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PostgreSQL
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.postgresql.org