Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120123
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2013-244)
Zusammenfassung:The remote host is missing an update for the 'postgresql8' package(s) announced via the ALAS-2013-244 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'postgresql8' package(s) announced via the ALAS-2013-244 advisory.

Vulnerability Insight:
An array index error, leading to a heap-based out-of-bounds buffer read flaw, was found in the way PostgreSQL performed certain error processing using enumeration types. An unprivileged database user could issue a specially crafted SQL query that, when processed by the server component of the PostgreSQL service, would lead to a denial of service (daemon crash) or disclosure of certain portions of server memory. (CVE-2013-0255)

A flaw was found in the way the pgcrypto contrib module of PostgreSQL (re)initialized its internal random number generator. This could lead to random numbers with less bits of entropy being used by certain pgcrypto functions, possibly allowing an attacker to conduct other attacks. (CVE-2013-1900)

Affected Software/OS:
'postgresql8' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:M/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-0255
BugTraq ID: 57844
http://www.securityfocus.com/bid/57844
Debian Security Information: DSA-2630 (Google Search)
http://www.debian.org/security/2013/dsa-2630
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:142
http://osvdb.org/89935
RedHat Security Advisories: RHSA-2013:1475
http://rhn.redhat.com/errata/RHSA-2013-1475.html
http://securitytracker.com/id?1028092
http://secunia.com/advisories/51923
http://secunia.com/advisories/52819
SuSE Security Announcement: openSUSE-SU-2013:0318 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-02/msg00059.html
SuSE Security Announcement: openSUSE-SU-2013:0319 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-02/msg00060.html
http://www.ubuntu.com/usn/USN-1717-1
XForce ISS Database: postgresql-enumrecv-dos(81917)
https://exchange.xforce.ibmcloud.com/vulnerabilities/81917
Common Vulnerability Exposure (CVE) ID: CVE-2013-1900
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html
Debian Security Information: DSA-2657 (Google Search)
http://www.debian.org/security/2013/dsa-2657
Debian Security Information: DSA-2658 (Google Search)
http://www.debian.org/security/2013/dsa-2658
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html
SuSE Security Announcement: SUSE-SU-2013:0633 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html
SuSE Security Announcement: openSUSE-SU-2013:0627 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html
SuSE Security Announcement: openSUSE-SU-2013:0628 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html
SuSE Security Announcement: openSUSE-SU-2013:0635 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html
http://www.ubuntu.com/usn/USN-1789-1
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.