LWN.net Logo

postgresql: information disclosure/denial of service

Package(s):postgresql CVE #(s):CVE-2013-0255
Created:February 11, 2013 Updated:February 21, 2013
Description: From the Red Hat bugzilla:

An array index error, leading to out of heap-based buffer bounds read flaw was found in the way PostgreSQL, an advanced Object-Relational database management system (DBMS), performed retrieval of textual form of error message representation when processing certain enumeration types. An unprivileged database user could issue a specially-crafted SQL query that, when processed by the server component of the PostgreSQL service, would lead to denial of service (daemon crash) or disclosure (of certain portions of) server memory.

Alerts:
Fedora FEDORA-2013-2123 2013-02-11
Ubuntu USN-1717-1 2013-02-12
Mageia MGASA-2013-0049 2013-02-13
Mandriva MDVSA-2013:012 2013-02-15
Fedora FEDORA-2013-2152 2013-02-17
Debian DSA-2630-1 2013-02-20
openSUSE openSUSE-SU-2013:0319-1 2013-02-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds