Release date:
Updated on:
Affected Systems:
PostgreSQL 9.3.x
PostgreSQL 9.2.x
PostgreSQL 9.1.x
PostgreSQL 9.0.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66557
CVE (CAN) ID: CVE-2014-2669
PostgreSQL is an advanced object-relational database management system that supports extended SQL standard subsets.
PostgreSQL 9.0.16, 9.1.12, 9.2.7, and 9.3.3 have multiple integer overflow vulnerabilities in contrib/hstore/hstore_io.c, authenticated remote users use the hstore_recv, resume, hstore_from_array and hstore_op.c functions in contrib/hstore/hstore_io.c to trigger buffer overflow, as a result, arbitrary code is executed in the context of the affected application.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PostgreSQL
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.postgresql.org
Https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a
PostgreSQL details: click here
PostgreSQL: click here
PostgreSQL cache details
Compiling PostgreSQL on Windows
Configuration and installation of LAPP (Linux + Apache + PostgreSQL + PHP) Environment in Ubuntu
Install and configure phppgAdmin on Ubuntu