CVE-2007-0555
PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.
- CVSS 2.0
- 8.5 HIGHAV:N/AC:L/Au:S/C:C/I:N/A:C
- EPSS
- 4.84% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- postgresql/postgresql
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.ascThird Party Advisory
- http://fedoranews.org/cms/node/2554Third Party Advisory
- http://lists.rpath.com/pipermail/security-announce/2007-February/000141.htmlBroken Link
- http://osvdb.org/33087Broken Link
- http://secunia.com/advisories/24028Broken Link
- http://secunia.com/advisories/24033Broken Link
- http://secunia.com/advisories/24042Broken Link
- http://secunia.com/advisories/24050Broken Link
- http://secunia.com/advisories/24057Broken Link
- http://secunia.com/advisories/24094Broken Link
- http://secunia.com/advisories/24151Broken Link
- http://secunia.com/advisories/24158Broken Link
- http://secunia.com/advisories/24284Broken Link
- http://secunia.com/advisories/24315Broken Link
- http://secunia.com/advisories/24513Broken Link
- http://secunia.com/advisories/24577Broken Link
- http://secunia.com/advisories/25220Broken Link
- http://security.gentoo.org/glsa/glsa-200703-15.xmlThird Party Advisory
- http://securitytracker.com/id?1017597Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2007-117.htmThird Party Advisory
- http://www.debian.org/security/2007/dsa-1261Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:037Broken Link
- http://www.novell.com/linux/security/advisories/2007_10_sr.htmlThird Party Advisory
- http://www.postgresql.org/support/securityVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0064.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0067.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0068.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/459280/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/459448/100/0/threadedThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.