LWN.net Logo

Buffer overflow vulnerabilities in PostgreSQL

Package(s):PostgreSQL CVE #(s):
Created:August 21, 2002 Updated:January 27, 2003
Description: PostgreSQL 7.2.2 has been released in response to a number of buffer overrun vulnerabilities which have been identified recently. "...it should be noted that these vulnerabilities are only critical on 'open' or 'shared' systems, as they require the ability to be able to connect to the database before they can be exploited."

Buffer overflow vulnerabilities fixed include those reported by "Sir Mordred The Traitor" in the cash_words, repeat, and lpad and rpad functions.

Alerts:
Gentoo postgresql-20020826 2002-08-26
Debian DSA-165-1 2002-09-12
Conectiva CLA-2002:524 2002-09-19
Mandrake MDKSA-2002:062 2002-10-01
Trustix 2002-0071 2002-10-17
SuSE SuSE-SA:2002:038 2002-10-21
Red Hat RHSA-2003:010-10 2003-01-14
Red Hat RHSA-2003:001-16 2003-01-14
Yellow Dog YDU-20030127-5 2003-01-27

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.