Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.56914
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2006:098 (postgresql)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to postgresql
announced via advisory MDKSA-2006:098.

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13,
7.3.x before 7.3.15, and earlier versions allows context-dependent
attackers to bypass SQL injection protection methods in applications
via invalid encodings of multibyte characters, aka one variant of
Encoding-Based SQL Injection. (CVE-2006-2313)

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13,
7.3.x before 7.3.15, and earlier versions allows context-dependent
attackers to bypass SQL injection protection methods in applications
that use multibyte encodings that allow the \ (backslash) byte 0x5c to
be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK,
GB18030, and UHC, which cannot be handled correctly by a client that does
not understand multibyte encodings, aka a second variant of Encoding-Based
SQL Injection. NOTE: it could be argued that this is a class of issue
related to interaction errors between the client and PostgreSQL, but a
CVE has been assigned since PostgreSQL is treating this as a preventative
measure against this class of problem. (CVE-2006-2314)

Packages have been patched or updated to correct these issues.

Affected: 10.2, 2006.0, Corporate 3.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2006:098

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2006-2313
BugTraq ID: 18092
http://www.securityfocus.com/bid/18092
Bugtraq: 20060523 PostgreSQL security releases 8.1.4, 8.0.8, 7.4.13, 7.3.15 (Google Search)
http://www.securityfocus.com/archive/1/435038/100/0/threaded
Bugtraq: 20060524 rPSA-2006-0080-1 postgresql postgresql-server (Google Search)
http://www.securityfocus.com/archive/1/435161/100/0/threaded
Debian Security Information: DSA-1087 (Google Search)
http://www.debian.org/security/2006/dsa-1087
http://security.gentoo.org/glsa/glsa-200607-04.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:098
http://archives.postgresql.org/pgsql-announce/2006-05/msg00010.php
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10618
http://www.redhat.com/support/errata/RHSA-2006-0526.html
http://securitytracker.com/id?1016142
http://secunia.com/advisories/20231
http://secunia.com/advisories/20232
http://secunia.com/advisories/20314
http://secunia.com/advisories/20435
http://secunia.com/advisories/20451
http://secunia.com/advisories/20503
http://secunia.com/advisories/20555
http://secunia.com/advisories/20653
http://secunia.com/advisories/20782
http://secunia.com/advisories/21001
SGI Security Advisory: 20060602-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
SuSE Security Announcement: SUSE-SA:2006:030 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0002.html
http://www.trustix.org/errata/2006/0032/
https://usn.ubuntu.com/288-1/
http://www.ubuntu.com/usn/usn-288-2
http://www.vupen.com/english/advisories/2006/1941
XForce ISS Database: postgresql-multibyte-sql-injection(26627)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26627
Common Vulnerability Exposure (CVE) ID: CVE-2006-2314
http://www.osvdb.org/25731
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9947
http://secunia.com/advisories/21749
SuSE Security Announcement: SUSE-SR:2006:021 (Google Search)
http://www.novell.com/linux/security/advisories/2006_21_sr.html
http://www.ubuntu.com/usn/usn-288-3
XForce ISS Database: postgresql-ascii-sql-injection(26628)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26628
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.