Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120552
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2013-178)
Zusammenfassung:The remote host is missing an update for the 'postgresql9' package(s) announced via the ALAS-2013-178 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'postgresql9' package(s) announced via the ALAS-2013-178 advisory.

Vulnerability Insight:
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a '-' (hyphen).

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the 'contrib/pgcrypto functions.'

Affected Software/OS:
'postgresql9' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:M/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-1899
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html
Debian Security Information: DSA-2658 (Google Search)
http://www.debian.org/security/2013/dsa-2658
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:142
SuSE Security Announcement: SUSE-SU-2013:0633 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html
SuSE Security Announcement: openSUSE-SU-2013:0627 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html
SuSE Security Announcement: openSUSE-SU-2013:0628 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html
SuSE Security Announcement: openSUSE-SU-2013:0635 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html
http://www.ubuntu.com/usn/USN-1789-1
Common Vulnerability Exposure (CVE) ID: CVE-2013-1900
Debian Security Information: DSA-2657 (Google Search)
http://www.debian.org/security/2013/dsa-2657
RedHat Security Advisories: RHSA-2013:1475
http://rhn.redhat.com/errata/RHSA-2013-1475.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-1901
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.